Known vulnerabilities in thunderbird
Vendor:
OpenAnolis
Software:
thunderbird
Software CPE:
cpe:2.3:o:openanolis:thunderbird:*:*:*:*:*:anolis_os:*:*
Website:
https://openanolis.cn/
Total vulnerabilities:
662
Public exploits:
12
Known exploited (KEV):
5
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
140.13.0-1.0.1
140.12.0-1.0.1
128.14.0-3.0.1
128.13.0-3.0.1
128.12.0-1.0.1
128.11.0-1.0.1
128.10.0-1.0.1
128.9.0-2.0.1
128.5.0-1.0.1
128.4.0-1.0.1
128.3.0-1.0.1
115.5.0-1.0.1
102.3.0-3.0.2
102.5.0-2.0.1
102.3.0-3.0.1
91.3.0-2.0.1
128.8.0-2.0.1
128.7.0-1.0.1
128.6.0-3.0.1
128.3.1-1.0.1
128.2.0-1.0.1
115.14.0-1.0.1
115.13.0-3.0.1
115.12.1-1.0.1
115.10.0-2.0.1
115.9.0-1.0.1
115.8.0-1.0.1
115.7.0-1.0.1
115.6.0-1.0.1
115.4.1-1.0.1
115.3.1-1.0.1
102.15.1-1.0.1
102.15.0-1.0.1
102.14.0-3.0.1
102.14.0-1.0.1
102.13.0-2.0.1
102.12.0-1.0.1
102.11.0-1.0.1
102.10.0-2.0.1
102.9.0-1.0.1
102.8.0-2.0.1
102.7.1-2.0.1
102.7.1-1.0.1
102.6.0-2.0.1
102.4.0-1.0.1
102.3.0-4.0.1
91.13.0-1.0.1
91.12.0-1.0.1
91.11.0-2.0.1
91.10.0-1.0.1
91.9.1-1.0.1
91.9.0-3.0.1
91.8.0-1.0.2
91.8.0-1.0.1
91.7.0-2.0.1
91.6.0-1.0.1
91.5.0-1.0.1
91.4.0-2.0.1
78.13.0-1.0.1
78.12.0-2.0.1
78.11.0-1.0.1
78.10.0-1.0.1
Vulnerabilities (662)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139188 - Off-by-one Error CVE-2026-14899 |
CWE-193 | Medium | 140.13.0-1.0.1 | 23.07.2026 |
SB2026072301 SB2026072302 SB2026080368 and 10 more |
||
| #VU138977 - Use After Free CVE-2026-16362 |
CWE-416 | High | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138978 - Incorrect Calculation CVE-2026-16363 |
CWE-682 | High | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138979 - Out-of-bounds read CVE-2026-16368 |
CWE-125 | Medium | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138980 - Integer overflow CVE-2026-16369 |
CWE-190 | High | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138964 - Improper Access Control CVE-2026-16349 |
CWE-284 | Medium | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138965 - Improper input validation CVE-2026-16350 |
CWE-20 | Medium | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138966 - Use After Free CVE-2026-16351 |
CWE-416 | High | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138967 - Use After Free CVE-2026-16352 |
CWE-416 | High | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138968 - NULL Pointer Dereference CVE-2026-16353 |
CWE-476 | Medium | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138969 - Exposure of sensitive information to an unauthorized actor CVE-2026-16354 |
CWE-200 | Medium | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138970 - Incorrect Calculation CVE-2026-16355 |
CWE-682 | High | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138971 - Use After Free CVE-2026-16356 |
CWE-416 | High | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138972 - Improper input validation CVE-2026-16357 |
CWE-20 | Medium | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138973 - Improper Access Control CVE-2026-16358 |
CWE-284 | Medium | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138974 - Improper input validation CVE-2026-16359 |
CWE-20 | Medium | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138975 - Memory corruption CVE-2026-16360 |
CWE-119 | High | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 18 more |
||
| #VU138976 - Memory corruption CVE-2026-16361 |
CWE-119 | High | 140.13.0-1.0.1 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072442 and 17 more |
||
| #VU137818 - Improper Access Control CVE-2026-15719 |
CWE-284 | High | 140.13.0-1.0.1 | 16.07.2026 |
SB2026071604 SB2026072301 SB2026072442 and 17 more |
||
| #VU137817 - Access of Uninitialized Pointer CVE-2026-15718 |
CWE-824 | High | 140.13.0-1.0.1 | 16.07.2026 |
SB2026071604 SB2026072301 SB2026072442 and 17 more |
Showing elements 1 - 20 out of 662