Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Thunderbird — Vulnerabilities & Security Advisories 306

All 306 CVE vulnerabilities found in Thunderbird, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting Mozilla Thunderbird, specifically focusing on software weaknesses and associated risk tags. It collects a comprehensive inventory of historical and recent security flaws, spanning the full lifecycle of the product from its initial release through the most recent updates. The dataset covers critical issues such as buffer overflows, memory safety errors, and cross-site scripting vectors that have impacted the email client over time. Here, you can track the vendor’s advisory history, analyze the prevalence of specific weakness classes, and review the complete vulnerability timeline for Thunderbird. The interface supports filtering by severity, component, and date range to facilitate detailed risk assessment. This resource serves security analysts, patch managers, and researchers who require a centralized view of known defects without navigating individual CVE entries. By consolidating these data points, the page enables efficient monitoring of emerging threats and historical patterns within the Mozilla ecosystem.

Vendor: Mozilla

CVE ID Title CVSS Severity Published
CVE-2026-84642 Allowed UNC hostnames for attachments interpreted as a regular expression - - 2026-09-01
CVE-2026-84641 Information disclosure due to malicious IMAP server response - - 2026-09-01
CVE-2026-84640 One byte overflow read in mail parser - - 2026-09-01
CVE-2026-84639 Uninitialized memory in MIME parsing - - 2026-09-01
CVE-2026-84637 Calendar invitation attachments could launch local executables - - 2026-09-01
CVE-2026-14899 Off-by-one out of bounds read in MIME header parser for forwarding - - 2026-07-22
CVE-2026-57963 Chat UI manipulation by injection - - 2026-07-01
CVE-2026-57962 Denial-of-service via malicious LDAP address-book server - - 2026-07-01
CVE-2026-4371 Out of bounds read in IMAP parsing 8.1 - 2026-03-24
CVE-2026-3889 Spoofing issue in Thunderbird 4.3 - 2026-03-24
CVE-2026-0818 CSS-based exfiltration of the content from partially encrypted emails when allowing remote content 6.5AI Medium AI 2026-01-28
CVE-2025-5986 Unsolicited File Download, Disk Space Exhaustion, and Credential Leakage via mailbox:/// Links 6.5AI Medium AI 2025-06-11
CVE-2025-5262 Mozilla Thunderbird 安全漏洞 9.8 - 2025-05-27
CVE-2025-3932 Tracking Links in Attachments Bypassed Remote Content Blocking 4.3AI Medium AI 2025-05-14
CVE-2025-3909 JavaScript Execution via Spoofed PDF Attachment and file:/// Link 6.1AI Medium AI 2025-05-14
CVE-2025-3875 Sender Spoofing via Malformed From Header in Thunderbird 4.3AI Medium AI 2025-05-14
CVE-2025-3523 User Interface (UI) Misrepresentation of attachment URL 7.4AI High AI 2025-04-15
CVE-2025-3522 Leak of hashed Window credentials via crafted attachment URL 7.1AI High AI 2025-04-15
CVE-2025-2830 Information Disclosure of /tmp directory listing 4.3AI Medium AI 2025-04-15
CVE-2025-26696 Crafted email message incorrectly shown as being encrypted 7.5 - 2025-03-10
CVE-2025-26695 Downloading of OpenPGP keys from WKD used incorrect padding 5.3 - 2025-03-10
CVE-2025-1015 Unsanitized address book fields 6.1 - 2025-02-04
CVE-2025-0510 Address of e-mail sender can be spoofed by malicious email 4.3 - 2025-02-04
CVE-2024-11159 Mozilla Thunderbird 安全漏洞 7.5AI High AI 2024-11-13
CVE-2024-8394 Mozilla Thunderbird 安全漏洞 7.5 - 2024-09-06
CVE-2024-1936 Mozilla Thunderbird 安全漏洞 6.5AI Medium AI 2024-03-04
CVE-2023-50761 Mozilla Thunderbird 安全漏洞 4.3AI Medium AI 2023-12-19
CVE-2023-50762 Mozilla Thunderbird 安全漏洞 6.5AI Medium AI 2023-12-19
CVE-2023-3417 File Extension Spoofing using the Text Direction Override Character 6.5 - 2023-07-24
CVE-2023-0616 Mozilla Firefox ESR 资源管理错误漏洞 6.5 - 2023-06-02

All 306 known CVE vulnerabilities affecting Thunderbird with full Chinese analysis, references, and POCs where available.