Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Thunderbird — Vulnerabilities & Security Advisories 270

All 270 CVE vulnerabilities found in Thunderbird, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerability data for Thunderbird, a popular open-source email client developed by the Mozilla Foundation. The collection includes a comprehensive range of weakness types such as buffer overflows, input validation errors, cross-site scripting flaws, and permission bypasses that have been identified within the software ecosystem. These entries cover security issues reported and patched from 2007 through the present, ensuring a historical perspective on the product’s security posture over its long development lifecycle. Visitors to this resource can track vendor advisories to understand how Mozilla responds to critical security threats in real-time. Users can also deepen their understanding of specific weakness classes by examining detailed technical descriptions and remediation strategies associated with Thunderbird. Additionally, the page allows for the lookup of a product’s vulnerability history, enabling security analysts and developers to assess risk trends and identify recurring patterns in code quality or architectural weaknesses. This structured approach facilitates better decision-making for system administrators and security researchers who rely on Thunderbird for communication infrastructure. By centralizing this information, the page serves as a vital reference for maintaining secure configurations and applying timely updates to mitigate potential exploitation vectors.

Vendor: Mozilla

CVE IDTitleCVSSSeverityPublished
CVE-2026-57963 Chat UI manipulation by injection --2026-07-01
CVE-2026-57962 Denial-of-service via malicious LDAP address-book server --2026-07-01
CVE-2026-4371 Out of bounds read in IMAP parsing 8.1 -2026-03-24
CVE-2026-3889 Spoofing issue in Thunderbird 4.3 -2026-03-24
CVE-2026-0818 CSS-based exfiltration of the content from partially encrypted emails when allowing remote content 6.5AIMediumAI2026-01-28
CVE-2025-5986 Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links 6.5AIMediumAI2025-06-11
CVE-2025-5262 Mozilla Thunderbird 安全漏洞 9.8 -2025-05-27
CVE-2025-3932 Tracking Links in Attachments Bypassed Remote Content Blocking 4.3AIMediumAI2025-05-14
CVE-2025-3909 JavaScript Execution via Spoofed PDF Attachment and file:/// Link 6.1AIMediumAI2025-05-14
CVE-2025-3875 Sender Spoofing via Malformed From Header in Thunderbird 4.3AIMediumAI2025-05-14
CVE-2025-3523 User Interface (UI) Misrepresentation of attachment URL 7.4AIHighAI2025-04-15
CVE-2025-3522 Leak of hashed Window credentials via crafted attachment URL 7.1AIHighAI2025-04-15
CVE-2025-2830 Information Disclosure of /tmp directory listing 4.3AIMediumAI2025-04-15
CVE-2025-26696 Crafted email message incorrectly shown as being encrypted 7.5 -2025-03-10
CVE-2025-26695 Downloading of OpenPGP keys from WKD used incorrect padding 5.3 -2025-03-10
CVE-2025-1015 Unsanitized address book fields 6.1 -2025-02-04
CVE-2025-0510 Address of e-mail sender can be spoofed by malicious email 4.3 -2025-02-04
CVE-2024-11159 Mozilla Thunderbird 安全漏洞 7.5AIHighAI2024-11-13
CVE-2024-8394 Mozilla Thunderbird 安全漏洞 7.5 -2024-09-06
CVE-2024-1936 Mozilla Thunderbird 安全漏洞 6.5AIMediumAI2024-03-04
CVE-2023-50761 Mozilla Thunderbird 安全漏洞 4.3AIMediumAI2023-12-19
CVE-2023-50762 Mozilla Thunderbird 安全漏洞 6.5AIMediumAI2023-12-19
CVE-2023-3417 File Extension Spoofing using the Text Direction Override Character 6.5 -2023-07-24
CVE-2023-0430 Mozilla Thunderbird 信任管理问题漏洞 --2023-06-02
CVE-2023-25746 Mozilla Firefox ESR 缓冲区错误漏洞 8.8 -2023-06-02
CVE-2023-1945 Mozilla Firefox ESR 缓冲区错误漏洞 8.8 -2023-06-02
CVE-2023-0547 Mozilla Thunderbird 信任管理问题漏洞 6.5 -2023-06-02
CVE-2023-0616 Mozilla Firefox ESR 资源管理错误漏洞 6.5 -2023-06-02
CVE-2021-43529 Mozilla Thunderbird 缓冲区错误漏洞 9.8 -2023-02-16
CVE-2022-28281 Mozilla Firefox 缓冲区错误漏洞 8.8 -2022-12-22

All 270 known CVE vulnerabilities affecting Thunderbird with full Chinese analysis, references, and POCs where available.