Mozilla

Thunderbird

2081 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 15.09.2026 12:33:27
  • Zuletzt bearbeitet 06.10.2026 14:48:27

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunder...

  • EPSS 0.27%
  • Veröffentlicht 15.09.2026 12:33:26
  • Zuletzt bearbeitet 06.10.2026 14:48:48

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunder...

  • EPSS 0.34%
  • Veröffentlicht 15.09.2026 12:33:25
  • Zuletzt bearbeitet 06.10.2026 14:49:12

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunder...

Medienbericht
  • EPSS 0.16%
  • Veröffentlicht 15.09.2026 12:33:24
  • Zuletzt bearbeitet 06.10.2026 14:42:00

Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

  • EPSS 0.29%
  • Veröffentlicht 01.09.2026 21:33:07
  • Zuletzt bearbeitet 03.09.2026 19:01:11

A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbir...

  • EPSS 0.27%
  • Veröffentlicht 01.09.2026 21:33:07
  • Zuletzt bearbeitet 03.09.2026 19:00:52

The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachment...

  • EPSS 0.34%
  • Veröffentlicht 01.09.2026 21:33:06
  • Zuletzt bearbeitet 03.09.2026 19:01:50

Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • EPSS 0.28%
  • Veröffentlicht 01.09.2026 21:33:06
  • Zuletzt bearbeitet 03.09.2026 19:01:32

A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • EPSS 0.34%
  • Veröffentlicht 01.09.2026 21:25:08
  • Zuletzt bearbeitet 03.09.2026 19:02:08

Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could al...

  • EPSS 0.15%
  • Veröffentlicht 01.09.2026 12:19:11
  • Zuletzt bearbeitet 03.09.2026 16:33:15

Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. Th...