Known vulnerabilities in Mozilla Thunderbird - page 16

Vendor: Mozilla
Software CPE: cpe:2.3:a:mozilla:mozilla_thunderbird:*:*:*:*:*:*:*:*
Total vulnerabilities: 1221
Public exploits: 32
Known exploited (KEV): 12
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Mozilla Thunderbird Mozilla Thunderbird is affected by 1221 known vulnerabilities: 10 critical, 549 high, 341 medium, 321 low Critical High Medium Low

Vulnerabilities (1221)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU121218 - Memory corruption
CVE-2026-0891
CWE-119 High
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121217 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2026-0890
CWE-451 Low
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121216 - Improper Restriction of Rendered UI Layers or Frames
CVE-2026-0887
CWE-1021 Medium
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121215 - Use After Free
CVE-2026-0885
CWE-416 Low
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121214 - Use After Free
CVE-2026-0884
CWE-416 Low
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121213 - Exposure of sensitive information to an unauthorized actor
CVE-2026-0883
CWE-200 Medium
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121211 - Memory corruption
CVE-2026-0886
CWE-119 High
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121210 - Integer overflow
CVE-2026-0880
CWE-190 High
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU121209 - Use After Free
CVE-2026-0882
CWE-416 High
No
No
140.7.0, 147.0 13.01.2026 SB2026011359
SB20260114138
SB2026011516
and 36 more
#VU119421 - Memory corruption
CVE-2025-14332
CWE-119 High
No
No
146.0 09.12.2025 SB2025120939
SB20251210204
#VU119420 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-14327
CWE-451 Medium
No
No
140.7.0, 146.0 09.12.2025 SB2025120939
SB20251210204
SB20260114138
and 36 more
#VU119419 - Use After Free
CVE-2025-14326
CWE-416 Medium
No
No
146.0 09.12.2025 SB2025120939
SB20251210204
#VU119417 - Improper input validation
CVE-2025-14330
CWE-20 Medium
No
No
140.6.0, 146.0 09.12.2025 SB2025120939
SB20251210189
SB20251210190
and 41 more
#VU119416 - Improper Privilege Management
CVE-2025-14329
CWE-269 Medium
No
No
140.6.0, 146.0 09.12.2025 SB2025120939
SB20251210189
SB20251210190
and 41 more
#VU119415 - Improper Privilege Management
CVE-2025-14328
CWE-269 Medium
No
No
140.6.0, 146.0 09.12.2025 SB2025120939
SB20251210189
SB20251210190
and 41 more
#VU119414 - Improper input validation
CVE-2025-14325
CWE-20 High
No
No
140.6.0, 146.0 09.12.2025 SB2025120939
SB20251210189
SB20251210190
and 41 more
#VU119413 - Use After Free
CVE-2025-14321
CWE-416 High
Available
No
140.6.0, 146.0 09.12.2025 SB2025120939
SB20251210189
SB20251210190
and 41 more
#VU119411 - Improper input validation
CVE-2025-14324
CWE-20 High
No
No
140.6.0, 146.0 09.12.2025 SB2025120939
SB20251210189
SB20251210190
and 41 more
#VU119410 - Improper Privilege Management
CVE-2025-14323
CWE-269 Medium
No
No
140.6.0, 146.0 09.12.2025 SB2025120939
SB20251210189
SB20251210190
and 41 more
#VU119409 - Memory corruption
CVE-2025-14322
CWE-119 High
No
No
140.6.0, 146.0 09.12.2025 SB2025120939
SB20251210189
SB20251210190
and 41 more


Showing elements 301 - 320 out of 1221