Mozilla / Thunderbird
1,917 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84642 | Allowed UNC hostnames for attachments interpreted as a regular expression | HIGH | 7.5 | Sep 1, 2026 |
| CVE-2026-84641 | Information disclosure due to malicious IMAP server response | HIGH | 7.5 | Sep 1, 2026 |
| CVE-2026-84640 | One byte overflow read in mail parser | HIGH | 7.5 | Sep 1, 2026 |
| CVE-2026-84639 | Uninitialized memory in MIME parsing | CRITICAL | 9.1 | Sep 1, 2026 |
| CVE-2026-84637 | Calendar invitation attachments could launch local executables | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84144 | Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2 | HIGH | 7.5 | Sep 1, 2026 |
| CVE-2026-84143 | Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15 | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84142 | Internally found bugs fixed in Thunderbird 155 | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84141 | Integer overflow in the Graphics: ImageLib component | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84140 | Site isolation issue in the DOM: Navigation component | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84139 | Clickjacking issue in the DOM: Events component | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84138 | Denial-of-service in the PDF Viewer component | HIGH | 7.5 | Sep 1, 2026 |
| CVE-2026-84137 | Spoofing issue in the DOM: Core & HTML component | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84136 | Other issue in the DOM: Navigation component | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84134 | Other issue in the Profile Backup component | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84133 | Site isolation issue in the DOM: Push Subscriptions component | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84132 | Information disclosure in the Networking: HTTP component | HIGH | 7.5 | Sep 1, 2026 |
| CVE-2026-84130 | Information disclosure in the Graphics: WebGPU component | HIGH | 7.5 | Sep 1, 2026 |
| CVE-2026-84129 | Site isolation issue in the DOM: Navigation component | CRITICAL | 9.8 | Sep 1, 2026 |
| CVE-2026-84128 | Privilege escalation in the WebDriver BiDi component | HIGH | 8.8 | Sep 1, 2026 |
| CVE-2026-84126 | Incorrect boundary conditions in the Layout: Grid component | HIGH | 7.5 | Sep 1, 2026 |
| CVE-2026-84125 | Use-after-free in the DOM: Core & HTML component | HIGH | 8.8 | Sep 1, 2026 |
| CVE-2026-84124 | Use-after-free in the DOM: Core & HTML component | HIGH | 7.5 | Sep 1, 2026 |
| CVE-2026-84123 | Privilege escalation due to use-after-free in the Graphics: WebGPU component | HIGH | 8.8 | Sep 1, 2026 |
| CVE-2026-84122 | Use-after-free in the Audio/Video component | HIGH | 7.5 | Sep 1, 2026 |
Showing 1 to 25 of 1,917 CVEs