Known vulnerabilities in Mozilla Thunderbird - page 22

Vendor: Mozilla
Software CPE: cpe:2.3:a:mozilla:mozilla_thunderbird:*:*:*:*:*:*:*:*
Total vulnerabilities: 1221
Public exploits: 32
Known exploited (KEV): 12
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Mozilla Thunderbird Mozilla Thunderbird is affected by 1221 known vulnerabilities: 10 critical, 549 high, 341 medium, 321 low Critical High Medium Low

Vulnerabilities (1221)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU108056 - Memory corruption
CVE-2025-4092
CWE-119 High
No
No
138.0 29.04.2025 SB2025042927
SB2025042928
SB2026020339
#VU108055 - Exposure of sensitive information to an unauthorized actor
CVE-2025-4090
CWE-200 Low
No
No
138.0 29.04.2025 SB2025042927
SB2025042928
#VU108054 - Improper input validation
CVE-2025-4089
CWE-20 Medium
No
No
138.0 29.04.2025 SB2025042927
SB2025042928
SB2026020339
#VU108049 - Memory corruption
CVE-2025-4091
CWE-119 High
No
No
128.10, 138.0 29.04.2025 SB2025042927
SB2025042928
SB2025042929
and 27 more
#VU107465 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-3523
CWE-451 Low
No
No
128.9.2, 137.0.2 15.04.2025 SB2025041536
SB2025041555
SB2025042487
and 13 more
#VU107464 - Exposure of sensitive information to an unauthorized actor
CVE-2025-2830
CWE-200 Low
No
No
128.9.2, 137.0.2 15.04.2025 SB2025041536
SB2025041555
SB2025042487
and 13 more
#VU107463 - Exposure of sensitive information to an unauthorized actor
CVE-2025-3522
CWE-200 Medium
No
No
128.9.2, 137.0.2 15.04.2025 SB2025041536
SB2025041555
SB2025042487
and 13 more
#VU106365 - Memory corruption
CVE-2025-3034
CWE-119 High
No
No
137.0 01.04.2025 SB2025040129
SB2025040130
SB20250403130
and 6 more
#VU106364 - Improper Link Resolution Before File Access ('Link Following')
CVE-2025-3033
CWE-59 Low
No
No
137.0 01.04.2025 SB2025040129
SB2025040130
#VU106362 - Missing release of memory after effective lifetime
CVE-2025-3032
CWE-401 Low
No
No
137.0 01.04.2025 SB2025040129
SB2025040130
SB20250403130
and 6 more
#VU106361 - Processor optimization removal or modification of security-critical code
CVE-2025-3031
CWE-1037 Low
No
No
137.0 01.04.2025 SB2025040129
SB2025040130
SB20250403130
and 6 more
#VU106360 - Memory corruption
CVE-2025-3030
CWE-119 High
No
No
128.9.0, 137.0 01.04.2025 SB2025040129
SB2025040130
SB2025040131
and 40 more
#VU106359 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-3029
CWE-451 Medium
No
No
128.9.0, 137.0 01.04.2025 SB2025040129
SB2025040130
SB2025040131
and 40 more
#VU106358 - Use After Free
CVE-2025-3028
CWE-416 High
No
No
128.9.0, 137.0 01.04.2025 SB2025040129
SB2025040130
SB2025040131
and 40 more
#VU105307 - Resource Management Errors
CVE-2025-1934
CWE-399 Medium
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105306 - Out-of-bounds write
CVE-2025-1932
CWE-787 High
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105303 - Memory corruption
CVE-2025-1933
CWE-119 High
No
No
128.8.0, 136.0 05.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105302 - Use After Free
CVE-2025-1931
CWE-416 High
No
No
128.8.0, 136.0 04.03.2025 SB2025030502
SB2025030503
SB2025030504
and 33 more
#VU105301 - Use After Free
CVE-2025-1930
CWE-416 High
No
No
128.8.0, 136.0 04.03.2025 SB2025030502
SB2025030503
SB2025030504
and 23 more
#VU101165 - Improper input validation
CVE-2024-43097
CWE-20 Low
No
No
128.8.0 03.12.2024 SB2024120367
SB2025030504
SB2025030505
and 16 more


Showing elements 421 - 440 out of 1221