« Volver al listado

Mozilla

Mozilla Thunderbird: vulnerabilidades y CVE

Mozilla Thunderbird tiene 1918 vulnerabilidades publicadas, 377 de ellas en los últimos 12 meses. 337 son críticas y 14 figuran en el catálogo de explotación activa de CISA.

CVE1918
Últimos 12 meses377
Críticas337
Explotadas activamente14

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2010-3765Crítica (9.8)83%⚠ Explotación activa28 oct 2010
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute…
CVE-2024-9680Crítica (9.8)23%⚠ Explotación activa9 oct 2024
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability…
CVE-2023-5217Alta (8.8)49%⚠ Explotación activa28 sept 2023
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security…
CVE-2023-4863Alta (8.8)100%⚠ Explotación activa12 sept 2023
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity:…
CVE-2016-9079Alta (7.5)87%⚠ Explotación activa11 jun 2018
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects…
CVE-2019-11708Crítica (10)56%⚠ Explotación activa23 jul 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process.…
CVE-2019-11707Alta (8.8)38%⚠ Explotación activa23 jul 2019
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This…
CVE-2013-1690Alta (8.8)69%⚠ Explotación activa26 jun 2013
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which…
CVE-2022-26486Crítica (9.6)2.3%⚠ Explotación activa22 dic 2022
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2,…
CVE-2022-26485Alta (8.8)14%⚠ Explotación activa22 dic 2022
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR <…
CVE-2013-1675Media (6.5)6.7%⚠ Explotación activa16 may 2013
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and…
CVE-2020-6819Alta (8.1)3.0%⚠ Explotación activa24 abr 2020
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird <…
CVE-2019-17026Alta (8.8)46%⚠ Explotación activa2 mar 2020
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR <…
CVE-2020-6820Alta (8.1)7.1%⚠ Explotación activa24 abr 2020
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0,…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-103500Sin puntuar0.19%—30 sept 2026
An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
CVE-2026-92240Crítica (9.1)0.63%—15 sept 2026
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before…
CVE-2026-92239Alta (8.1)0.41%—15 sept 2026
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-92238Crítica (9.8)0.54%—15 sept 2026
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVE-2026-84642Alta (7.5)0.42%—1 sept 2026
The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also…
CVE-2026-84641Alta (7.5)0.27%—1 sept 2026
A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155,…
CVE-2026-84640Alta (7.5)0.26%—1 sept 2026
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CVE-2026-84639Crítica (9.1)0.32%—1 sept 2026
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CVE-2026-84637Crítica (9.8)0.63%—1 sept 2026
Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display…
CVE-2026-84145Alta (7.5)0.37%—1 sept 2026
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with…
CVE-2026-84144Alta (7.5)0.43%—1 sept 2026
Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of…
CVE-2026-84143Crítica (9.8)0.38%—1 sept 2026
Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with…
CVE-2026-84142Crítica (9.8)0.56%—1 sept 2026
Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been…
CVE-2026-84141Crítica (9.8)0.63%—1 sept 2026
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84140Crítica (9.8)0.29%—1 sept 2026
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84139Media (6.1)0.34%—1 sept 2026
Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84138Media (6.5)0.37%—1 sept 2026
Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
CVE-2026-84137Media (4.3)0.21%—1 sept 2026
Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84136Media (6.1)0.38%—1 sept 2026
Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84134Crítica (9.8)0.57%—1 sept 2026
Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84133Crítica (9.8)0.29%—1 sept 2026
Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84132Alta (7.5)0.44%—1 sept 2026
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84131Alta (8.8)0.34%—1 sept 2026
Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and…
CVE-2026-84130Alta (7.5)0.44%—1 sept 2026
Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84129Crítica (9.8)0.29%—1 sept 2026
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84128Alta (8.8)0.44%—1 sept 2026
Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
CVE-2026-84126Media (4.3)0.31%—1 sept 2026
Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.
CVE-2026-84125Media (5.4)0.29%—1 sept 2026
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
CVE-2026-84124Media (5.4)0.17%—1 sept 2026
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CVE-2026-84123Alta (8.8)0.44%—1 sept 2026
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter8
  2. T1203 Exploitation for Client Execution8
  3. T1190 Exploit Public-Facing Application6
  4. T1059.007 JavaScript3
  5. T1005 Data from Local System2
  6. T1059.003 Windows Command Shell1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Mozilla