Known Vulnerabilities for Thunderbird by Mozilla
Listed below are 10 of the newest known vulnerabilities associated with "Thunderbird" by "Mozilla".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103500 json | An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in siz... | Not Provided | 2026-09-30 | 2026-09-30 |
| CVE-2026-100832 json | Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 140.17, Th... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-100831 json | Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbi... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-100830 json | Mitigation bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thund... | Not Provided | 2026-09-29 | 2026-10-01 |
| CVE-2026-100829 json | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunder... | Not Provided | 2026-09-29 | 2026-10-01 |
| CVE-2026-100828 json | Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, T... | Not Provided | 2026-09-29 | 2026-10-01 |
| CVE-2026-100826 json | Denial-of-service in the Storage: StorageManager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 15... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-100825 json | Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, T... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-100824 json | Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird... | Not Provided | 2026-09-29 | 2026-09-30 |
| CVE-2026-100822 json | Spoofing issue in the Networking: HTTP component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunder... | Not Provided | 2026-09-29 | 2026-09-30 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Thunderbird | 9.0.1 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 9.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 8.0 | |||
| Application | Mozilla | Thunderbird | 78.6.0 | |||
| Application | Mozilla | Thunderbird | 78.5.1 | |||
| Application | Mozilla | Thunderbird | 78.4.0 | |||
| Application | Mozilla | Thunderbird | 78.3 | |||
| Application | Mozilla | Thunderbird | 78.2 | |||
| Application | Mozilla | Thunderbird | 78.1.1 | |||
| Application | Mozilla | Thunderbird | 78.1.0 |