Known vulnerabilities in thunderbird (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:thunderbird_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 728
Public exploits: 24
Known exploited (KEV): 9
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting thunderbird (Debian package) thunderbird (Debian package) is affected by 728 known vulnerabilities: 8 critical, 347 high, 232 medium, 141 low Critical High Medium Low

Vulnerabilities (728)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139188 - Off-by-one Error
CVE-2026-14899
CWE-193 Medium
No
No
1:140.13.0esr-2~deb13u1 23.07.2026 SB2026072301
SB2026072302
SB2026080368
and 10 more
#VU138977 - Use After Free
CVE-2026-16362
CWE-416 High
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138978 - Incorrect Calculation
CVE-2026-16363
CWE-682 High
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138979 - Out-of-bounds read
CVE-2026-16368
CWE-125 Medium
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138980 - Integer overflow
CVE-2026-16369
CWE-190 High
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138964 - Improper Access Control
CVE-2026-16349
CWE-284 Medium
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138965 - Improper input validation
CVE-2026-16350
CWE-20 Medium
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138966 - Use After Free
CVE-2026-16351
CWE-416 High
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138967 - Use After Free
CVE-2026-16352
CWE-416 High
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138968 - NULL Pointer Dereference
CVE-2026-16353
CWE-476 Medium
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138969 - Exposure of sensitive information to an unauthorized actor
CVE-2026-16354
CWE-200 Medium
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138970 - Incorrect Calculation
CVE-2026-16355
CWE-682 High
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138971 - Use After Free
CVE-2026-16356
CWE-416 High
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138972 - Improper input validation
CVE-2026-16357
CWE-20 Medium
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138973 - Improper Access Control
CVE-2026-16358
CWE-284 Medium
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138974 - Improper input validation
CVE-2026-16359
CWE-20 Medium
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138975 - Memory corruption
CVE-2026-16360
CWE-119 High
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072302
and 18 more
#VU138976 - Memory corruption
CVE-2026-16361
CWE-119 High
No
No
1:140.13.0esr-2~deb13u1 21.07.2026 SB2026072201
SB2026072301
SB2026072442
and 17 more
#VU137818 - Improper Access Control
CVE-2026-15719
CWE-284 High
No
No
1:140.13.0esr-2~deb13u1 16.07.2026 SB2026071604
SB2026072301
SB2026072442
and 17 more
#VU137817 - Access of Uninitialized Pointer
CVE-2026-15718
CWE-824 High
No
No
1:140.13.0esr-2~deb13u1 16.07.2026 SB2026071604
SB2026072301
SB2026072442
and 17 more


Showing elements 1 - 20 out of 728