Thunderbird
Vendor:
First CVE: Aug 6, 2004 · Active for 21 years
1,775
Total CVEs
More Total CVEs than 100% of tracked products
77.2
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.8%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Thunderbird over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 6, 2004
21 years ago
Most Recent CVE
Jul 1, 2026
23 days ago
CVE Severity & Scoring
Thunderbird1,775 CVEs
34%
49%
15%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local35 (2.0%)
Network1,090 (61.4%)
Unknown650 (36.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1,030 (58.0%)
High95 (5.4%)
Unknown650 (36.6%)
User Interaction
None540 (30.4%)
Unknown650 (36.6%)
Required585 (33.0%)
Privileges Required
Low24 (1.4%)
High2 (0.1%)
None1,099 (61.9%)
Unknown650 (36.6%)
Top CVEs
Signals from CVEs in this product scope (1775 CVEs).
1,775 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-9079HIGH A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users | Jun 11, 2018 | 7.5 | 97 | YES | YES |
CVE-2010-3765CRITICAL Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, | Oct 28, 2010 | 9.8 | 97 | YES | YES |
CVE-2023-4863HIGH Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag | Sep 12, 2023 | 8.8 | 96 | YES | NO |
CVE-2013-1690HIGH Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in c | Jun 26, 2013 | 8.8 | 96 | YES | YES |
CVE-2019-11708CRITICAL Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content cho | Jul 23, 2019 | 10.0 | 94 | YES | YES |
CVE-2019-17026HIGH Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. Thi | Mar 2, 2020 | 8.8 | 90 | YES | YES |
CVE-2019-11707HIGH A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks | Jul 23, 2019 | 8.8 | 89 | YES | YES |
CVE-2023-5217HIGH Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra | Sep 28, 2023 | 8.8 | 87 | YES | NO |
CVE-2014-1510CRITICAL The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbit | Mar 19, 2014 | 9.8 | 87 | NO | YES |
CVE-2011-2371HIGH Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attac | Jun 30, 2011 | 10.0 | 86 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (1775 CVEs).
CISA KEV
14 CVEs
0.8% of CVEs· 96th percentile
Metasploit
18 CVEs
1.0% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
54 CVEs
3.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (1775 CVEs).
Media Mentions
Signals from CVEs in this product scope (1775 CVEs).
Top CNAs Publishing CVEs For Thunderbird
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0.1 | 56 | 7.5 | 4.3% | 0 | 1 |
| 9.0 | 61 | 7.4 | 4.1% | 0 | 1 |
| 8.0 | 66 | 7.5 | 5.1% | 0 | 2 |
| 7.0.1 | 62 | 7.5 | 4.1% | 0 | 1 |
| 7.0 | 74 | 7.5 | 3.9% | 0 | 1 |
| 6.0.2 | 73 | 7.5 | 3.9% | 0 | 1 |
| 6.0.1 | 73 | 7.5 | 3.9% | 0 | 1 |
| 6.0 | 74 | 7.4 | 3.9% | 0 | 1 |
| 52.9.1 | 1 | 8.8 | 4.7% | 0 | 0 |
| 52.4.0 | 1 | 7.5 | 3.1% | 0 | 0 |
| 5.0 | 81 | 7.4 | 3.8% | 0 | 1 |
| 38.1 | 1 | 3.7 | 99.9% | 0 | 1 |
| 3.1.9 | 50 | 7.9 | 5.6% | 0 | 2 |
| 31.8 | 1 | 3.7 | 99.9% | 0 | 1 |
| 3.1.8 | 59 | 8.1 | 5.5% | 0 | 2 |
| 3.1.7 | 68 | 8.3 | 5.4% | 0 | 2 |
| 3.1.6 | 76 | 8.3 | 5.4% | 0 | 2 |
| 3.1.5 | 77 | 8.4 | 6.4% | 1 | 3 |
| 3.1.4 | 90 | 8.3 | 5.9% | 1 | 4 |
| 31.3 | 5 | 6.0 | 2.9% | 0 | 0 |