VulnSea

Thunderbird vulnerabilities

CVEs whose affected-version data names the Thunderbird package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

142 CVEsRSS

CVE-2026-92059Critical· 9.3⚖ disputed
6d ago

Incorrect boundary conditions in the DOM: Editor component

Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92058High· 8.8⚖ disputed
6d ago

Use-after-free in the Graphics component

Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.25%via NVD
CVE-2026-92057Critical· 9.1⚖ disputed
6d ago

Mitigation bypass in the Enterprise Policies component

Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-92063Medium· 6.5⚖ disputed
6d ago

Denial-of-service in the Audio/Video component

Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

SunlitMozilla · FirefoxEPSS 0.22%via NVD
CVE-2026-92062High· 8.8⚖ disputed
6d ago

Privilege escalation in the Session Restore component

Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.24%via NVD
CVE-2026-92060High· 8.8⚖ disputed
6d ago

Use-after-free in the Internationalization component

Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.25%via NVD
CVE-2026-92066Critical· 9.8⚖ disputed
6d ago

Sandbox escape in the Profile Backup component

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

MidnightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92061Critical· 9.8⚖ disputed
6d ago

Incorrect boundary conditions in the Security: Process Sandboxing component

Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

MidnightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92070Low· 3.4
6d ago

Information disclosure in the Networking component

Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92069Low· 3.4
6d ago

Spoofing issue in the DOM: Navigation component

Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92067High· 8.8⚖ disputed
6d ago

Use-after-free in the Widget: Gtk component

Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.25%via NVD
CVE-2026-92071Low· 3.4
6d ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92068Low· 3.4
6d ago

Site isolation issue in the Reader Mode component

Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92064High· 8.8⚖ disputed
6d ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92073High· 8.8⚖ disputed
6d ago

Privilege escalation in the Enterprise Policies component

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.24%via NVD
CVE-2026-92072None
6d ago

Incorrect boundary conditions in the Safe Browsing component

Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92065High· 8.8⚖ disputed
6d ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-84639Critical· 9.1
2w ago

Uninitialized memory in MIME parsing

Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

MidnightMozilla · ThunderbirdEPSS 0.32%via CVEORG
CVE-2026-74983High· 8.1
1mo ago

Mitigation bypass in the Data Loss Prevention component

Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

TwilightMozilla · FirefoxEPSS 0.33%via CVEORG
CVE-2026-74961Critical· 9.1
1mo ago

Side-channel in the Web Audio component

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

MidnightMozilla · FirefoxEPSS 0.25%via CVEORG
CVE-2026-74944Critical· 9.8⚖ disputed
1mo ago

Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Midnightmozilla · firefoxEPSS 0.40%via NVD
CVE-2026-74943Critical· 9.8PoC⚖ disputed
1mo ago

Use-after-free in the Graphics: ImageLib component

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Abyssalmozilla · firefoxEPSS 0.57%via NVD
CVE-2026-74940Critical· 9.8⚖ disputed
1mo ago

Use-after-free in the Graphics: Text component

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Midnightmozilla · firefoxEPSS 0.41%via NVD
CVE-2026-74936Critical· 9.8PoC⚖ disputed
1mo ago

Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Abyssalmozilla · firefoxEPSS 0.40%via NVD
CVE-2026-56211High· 7.1
3mo ago

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted vide…

TwilightRed Hat · aomEPSS 0.48%via NVD
CVE-2026-56210High· 7.1
3mo ago

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation

A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the co…

TwilightRed Hat · aomEPSS 0.31%via NVD
CVE-2026-56209High· 7.1
3mo ago

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation

An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer i…

TwilightRed Hat · aomEPSS 0.35%via NVD
CVE-2026-56208High· 7.6
3mo ago

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation

A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when …

TwilightRed Hat · firefoxEPSS 0.42%via NVD
CVE-2026-12329Medium· 5.3
3mo ago

Memory safety bug fixed in Thunderbird ESR 140.12

Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.

Sunlitmozilla · firefoxEPSS 0.31%via NVD
CVE-2026-12328High· 8.1
3mo ago

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151

Memory safety bugs present in Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird ESR 140.11, Firefox 151 and Thunderbird 151. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these c…

Twilightmozilla · firefoxEPSS 0.48%via NVD
Thunderbird vulnerabilities (CVEs) — page 3 · VulnSea