mozilla / thunderbird
172 known vulnerabilities in mozilla thunderbird.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-74948 | Low | 0.3% | 6.5 | Information disclosure in the Graphics component. This vulnerability was fixed i… | |
| CVE-2026-74971 | Low | 0.3% | 4.3 | Information disclosure in the DOM: UI Events & Focus Handling component. This vu… | |
| CVE-2026-74972 | Low | 0.3% | 4.3 | Information disclosure in the DOM: Push Subscriptions component. This vulnerabil… | |
| CVE-2026-84120 | Low | 0.2% | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Fir… | |
| CVE-2026-84122 | Low | 0.2% | 5.4 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Fir… | |
| CVE-2026-8971 | Low | 0.2% | 6.5 | Same-origin policy bypass in the Networking: JAR component. This vulnerability w… | |
| CVE-2026-84118 | Low | 0.2% | 5.4 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in … | |
| CVE-2026-84138 | Low | 0.2% | 6.5 | Denial-of-service in the PDF Viewer component. This vulnerability was fixed in F… | |
| CVE-2026-84136 | Low | 0.2% | 6.1 | Other issue in the DOM: Navigation component. This vulnerability was fixed in Fi… | |
| CVE-2026-16403 | Low | 0.2% | 6.5 | Spoofing issue in the Address Bar component. This vulnerability was fixed in Fir… | |
| CVE-2026-74984 | Low | 0.2% | 6.8 | Race condition in the JavaScript Engine component. This vulnerability was fixed … | |
| CVE-2026-84139 | Low | 0.2% | 6.1 | Clickjacking issue in the DOM: Events component. This vulnerability was fixed in… | |
| CVE-2026-84126 | Low | 0.2% | 4.3 | Incorrect boundary conditions in the Layout: Grid component. This vulnerability … | |
| CVE-2026-74973 | Low | 0.2% | 4.2 | Race condition, use-after-free in the Graphics component. This vulnerability was… | |
| CVE-2026-84124 | Low | 0.2% | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-84125 | Low | 0.2% | 5.4 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-74970 | Low | 0.1% | 5.4 | Site isolation issue in the Graphics component. This vulnerability was fixed in … | |
| CVE-2026-74974 | Low | 0.1% | 5.4 | Same-origin policy bypass in the Graphics: ImageLib component. This vulnerabilit… | |
| CVE-2026-84137 | Low | 0.1% | 4.3 | Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed i… | |
| CVE-2026-74963 | Low | 0.1% | 5.4 | Same-origin policy bypass in the Networking: Cookies component. This vulnerabili… | |
| CVE-2026-74967 | Low | 0.1% | 5.4 | Same-origin policy bypass in the Audio/Video: Playback component. This vulnerabi… | |
| CVE-2026-74968 | Low | 0.1% | 5.4 | Site isolation issue in the Graphics: WebRender component. This vulnerability wa… |
← Prev Page 4 of 4