Mozilla

Thunderbird

2081 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.34%
  • Veröffentlicht 29.09.2026 13:17:40
  • Zuletzt bearbeitet 30.09.2026 18:18:03

Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

  • EPSS 0.15%
  • Veröffentlicht 29.09.2026 13:17:40
  • Zuletzt bearbeitet 01.10.2026 15:17:18

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

  • EPSS 0.25%
  • Veröffentlicht 29.09.2026 13:17:40
  • Zuletzt bearbeitet 30.09.2026 18:18:03

Privilege escalation due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.

  • EPSS 0.31%
  • Veröffentlicht 29.09.2026 13:17:40
  • Zuletzt bearbeitet 30.09.2026 18:18:03

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.

  • EPSS 0.27%
  • Veröffentlicht 29.09.2026 13:17:40
  • Zuletzt bearbeitet 30.09.2026 18:18:04

Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

  • EPSS 0.34%
  • Veröffentlicht 29.09.2026 13:17:40
  • Zuletzt bearbeitet 06.10.2026 14:37:11

Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

Medienbericht
  • EPSS 0.33%
  • Veröffentlicht 29.09.2026 13:17:39
  • Zuletzt bearbeitet 06.10.2026 14:37:17

Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

  • EPSS 0.21%
  • Veröffentlicht 15.09.2026 19:42:53
  • Zuletzt bearbeitet 24.09.2026 14:15:03

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fi...

  • EPSS 0.18%
  • Veröffentlicht 15.09.2026 19:42:52
  • Zuletzt bearbeitet 24.09.2026 14:15:31

A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

  • EPSS 0.18%
  • Veröffentlicht 15.09.2026 19:42:51
  • Zuletzt bearbeitet 24.09.2026 14:15:49

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.