Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Thunderbird — Vulnerabilities & Security Advisories 306

All 306 CVE vulnerabilities found in Thunderbird, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting Mozilla Thunderbird, specifically focusing on software weaknesses and associated risk tags. It collects a comprehensive inventory of historical and recent security flaws, spanning the full lifecycle of the product from its initial release through the most recent updates. The dataset covers critical issues such as buffer overflows, memory safety errors, and cross-site scripting vectors that have impacted the email client over time. Here, you can track the vendor’s advisory history, analyze the prevalence of specific weakness classes, and review the complete vulnerability timeline for Thunderbird. The interface supports filtering by severity, component, and date range to facilitate detailed risk assessment. This resource serves security analysts, patch managers, and researchers who require a centralized view of known defects without navigating individual CVE entries. By consolidating these data points, the page enables efficient monitoring of emerging threats and historical patterns within the Mozilla ecosystem.

Vendor: Mozilla

CVE ID Title CVSS Severity Published
CVE-2026-103500 Heap buffer overflow opening large email - - 2026-09-30
CVE-2026-100820 Privilege escalation in the Address Bar component - - 2026-09-29
CVE-2026-100818 Sandbox escape due to use-after-free in the Widget: Gtk component - - 2026-09-29
CVE-2026-100817 Other issue in the JavaScript: WebAssembly component - - 2026-09-29
CVE-2026-100813 Invalid pointer in the JavaScript Engine: JIT component - - 2026-09-29
CVE-2026-100811 Sandbox escape due to use-after-free in the DOM: Core & HTML component - - 2026-09-29
CVE-2026-100810 Other issue in the DevTools component - - 2026-09-29
CVE-2026-100807 Privilege escalation in the DOM: Service Workers component - - 2026-09-29
CVE-2026-100804 Sandbox escape due to use-after-free in the Preferences: Backend component - - 2026-09-29
CVE-2026-100805 Race condition, use-after-free in the Audio/Video component - - 2026-09-29
CVE-2026-100802 Uninitialized memory in the Graphics: WebGPU component - - 2026-09-29
CVE-2026-100801 Privilege escalation in the DLL Services component - - 2026-09-29
CVE-2026-100799 Uninitialized memory in the Graphics: WebGPU component - - 2026-09-29
CVE-2026-100796 Use-after-free in the JavaScript: WebAssembly component - - 2026-09-29
CVE-2026-100795 Denial-of-service in the Networking component - - 2026-09-29
CVE-2026-100794 Sandbox escape due to incorrect boundary conditions in the Internationalization component - - 2026-09-29
CVE-2026-96869 Information disclosure in the Networking component - - 2026-09-29
CVE-2026-100793 JIT miscompilation in the JavaScript Engine component - - 2026-09-29
CVE-2026-100792 JIT miscompilation in the JavaScript: WebAssembly component - - 2026-09-29
CVE-2026-100788 Invalid pointer in the JavaScript: WebAssembly component - - 2026-09-29
CVE-2026-100776 Use-after-free in the JavaScript: WebAssembly component - - 2026-09-29
CVE-2026-100772 Use-after-free in the DOM: Core & HTML component - - 2026-09-29
CVE-2026-100768 Use-after-free in the Graphics: WebGPU component - - 2026-09-29
CVE-2026-100769 Use-after-free in the JavaScript: WebAssembly component - - 2026-09-29
CVE-2026-100764 Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component - - 2026-09-29
CVE-2026-100763 Incorrect boundary conditions in the Graphics: WebGPU component - - 2026-09-29
CVE-2026-100761 Privilege escalation due to use-after-free in the Graphics: WebGPU component - - 2026-09-29
CVE-2026-92240 Out-of-bounds read in IMAP response parser - - 2026-09-15
CVE-2026-92239 Buffer overrun in IMAP - - 2026-09-15
CVE-2026-92238 Ambiguous parsing of mail headers - - 2026-09-15

All 306 known CVE vulnerabilities affecting Thunderbird with full Chinese analysis, references, and POCs where available.