Known vulnerabilities in Mozilla Thunderbird 128.1.1 - page 10

Vendor: Mozilla
Version: 128.1.1
Software CPE: cpe:2.3:a:mozilla:mozilla_thunderbird:*:*:*:*:*:*:*:*
Total vulnerabilities: 363
Public exploits: 4
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Mozilla Thunderbird version 128.1.1 Mozilla Thunderbird 128.1.1 is affected by 363 vulnerabilities: 1 critical, 193 high, 108 medium, 61 low Critical High Medium Low

Vulnerabilities (363)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU123204 - Protection Mechanism Failure
CVE-2026-2768
CWE-693 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU123203 - Use After Free
CVE-2026-2767
CWE-416 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU123201 - Use After Free
CVE-2026-2765
CWE-416 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU123189 - Memory corruption
CVE-2026-2776
CWE-119 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 33 more
#VU123188 - Protection Mechanism Failure
CVE-2026-2775
CWE-693 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU123187 - Integer overflow
CVE-2026-2774
CWE-190 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU123186 - Memory corruption
CVE-2026-2773
CWE-119 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 35 more
#VU123185 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-2771
CWE-74 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU123184 - Use After Free
CVE-2026-2772
CWE-416 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU123183 - Use After Free
CVE-2026-2770
CWE-416 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU123182 - Use After Free
CVE-2026-2769
CWE-416 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU123181 - Use After Free
CVE-2026-2764
CWE-416 High
No
No
140.8.0, 148.0 24.02.2026 SB2026022446
SB2026022526
SB2026022527
and 34 more
#VU122970 - Heap-based Buffer Overflow
CVE-2026-2447
CWE-122 High
No
No
140.7.2, 147.0.2 16.02.2026 SB20260216163
SB20260216169
SB2026022003
and 43 more
#VU121213 - Exposure of sensitive information to an unauthorized actor
CVE-2026-0883
CWE-200 Medium
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121212 - Memory corruption
CVE-2026-0878
CWE-119 High
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121210 - Integer overflow
CVE-2026-0880
CWE-190 High
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121209 - Use After Free
CVE-2026-0882
CWE-416 High
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121208 - Memory corruption
CVE-2026-0879
CWE-119 High
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121207 - Protection Mechanism Failure
CVE-2026-0877
CWE-693 High
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU119420 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-14327
CWE-451 Medium
No
No
140.7.0, 146.0 09.12.2025 SB2025120939
SB20251210204
SB20260114138
and 36 more


Showing elements 181 - 200 out of 363