Where
-Infinity
0

Mozilla ThunderbirdSecurity Vulnerabilities fixed in Thunderbird 128.11.1

Risk 33
Severity
7
First published (updated )
Advisory
MFSA2025-49

Mozilla ThunderbirdSecurity Vulnerabilities fixed in Thunderbird 139.0.2

Risk 33
Severity
7
First published (updated )
Advisory
MFSA2025-50

Mozilla Firefox ESRMemory safety bug present in Firefox ESR 128.10, and Thunderbird 128.10. This bug showed evidence of…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxMemory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.…

Risk 19
Severity
4
First published (updated )

Mozilla ThunderbirdDouble Free

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdSecurity Vulnerabilities fixed in Thunderbird 128.10.2

Risk 42
Severity
9
First published (updated )
Advisory
MFSA2025-40

Mozilla ThunderbirdSecurity Vulnerabilities fixed in Thunderbird 138.0.2

Risk 42
Severity
9
First published (updated )
Advisory
MFSA2025-41

Mozilla ThunderbirdIt was possible to craft an email that showed a tracking link as an attachment. If the user attempte…

Risk 5
Severity
1
First published (updated )

Mozilla ThunderbirdThunderbird parses addresses in a way that can allow sender spoofing in case the server allows an in…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdThunderbird's handling of the X-Mozilla-External-Attachment-URL header can be exploited to execute J…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdA crafted HTML email using mailbox:/// links can trigger automatic, unsolicited downloads of .pdf fi…

Risk 37
First published (updated )

Mozilla Thunderbird1 vulnerability

Risk 33
Severity
7
First published (updated )
Advisory
MFSA2025-34

Infoleak

Risk 33
Severity
7
First published (updated )

Mozilla Thunderbird1 vulnerability

Risk 33
Severity
7
First published (updated )
Advisory
MFSA2025-35

Infoleak

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdMozilla Firefox's update mechanism allowed a medium-integrity user process to interfere with the SYS…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdMemory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdA process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, whi…

Risk 33
Severity
7
First published (updated )

Mozilla Firefox ESRMemory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of m…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdA vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due t…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxA security vulnerability in Firefox allowed malicious sites to use redirects to send credentialed re…

Risk 19
Severity
4
First published (updated )

Mozilla FirefoxDue to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could …

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdAn attacker with control over a content process could potentially leverage the privileged UITour act…

Risk 19
Severity
4
First published (updated )

Mozilla ThunderbirdMemory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdA vulnerability existed in Firefox for Android where potentially sensitive library locations were lo…

Risk 5
Severity
1
First published (updated )

Mozilla Thunderbird4 vulnerabilities

Risk 33
Severity
7
First published (updated )
Advisory
MFSA2025-32

Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9…

Risk 19
Severity
4
First published (updated )

Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when ch…

Risk 33
Severity
7
First published (updated )

A vulnerability was identified in Firefox where XPath parsing could trigger undefined behavior due t…

Risk 19
Severity
4
First published (updated )

A process isolation vulnerability in Firefox stemmed from improper handling of javascript: URIs, whi…

Risk 33
Severity
7
First published (updated )

Mozilla ThunderbirdA specially crafted filename containing a large number of encoded newline characters could obscure t…

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203