Where
-Infinity
0

Vendor Risk Score

See how thunderbird compares to other vendors in security performance

View Risk Score →

BleepingComputerLastPass: Fake password managers infect Mac users with malware

First published (updated )

Mozilla ThunderbirdInfoleak

Risk 61
Severity
8.1
First published (updated )

matrix Javascript Sdk Node.jsMatrix Javascript SDK vulnerable to impersonation via forwarded Megolm sessions

Risk 45
Severity
7.5
First published (updated )

matrix Javascript Sdk Node.jsMatrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verification

Risk 50
Severity
8.6
First published (updated )

matrix Javascript Sdk Node.jsMatrix Javascript SDK vulnerable to Olm/Megolm protocol confusion

Risk 50
Severity
8.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

matrix Javascript Sdk Node.jsMatrix Javascript SDK improper beacon events can cause availability issues

Risk 28
Severity
5.3
First published (updated )

Mozilla ThunderbirdWhen saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.qua…

Risk 70
Severity
7.8
First published (updated )

matrix Javascript Sdk Node.jsPrototype pollution in matrix-js-sdk

Risk 56
Severity
8.2
First published (updated )

Mozilla ThunderbirdWhen displaying the sender of an email, and the sender name contained the Braille Pattern Blank spac…

Risk 38
Severity
6.5
First published (updated )

Mozilla FirefoxAn attacker could have sent a message to the parent process where the contents were used to double-i…

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla FirefoxIf an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollut…

Risk 79
Severity
8.8
First published (updated )

Mozilla ThunderbirdWhen viewing an email message A, which contains an attached message B, where B is encrypted or digit…

Risk 23
Severity
4.3
First published (updated )

Mozilla ThunderbirdThe parent process would not properly check whether the Speech Synthesis feature is enabled, when re…

Risk 38
Severity
6.5
First published (updated )

Mozilla ThunderbirdWhen receiving an OpenPGP/MIME signed email message that contains an additional outer MIME message l…

Risk 38
Severity
6.5
First published (updated )

Debian Debian LinuxBuffer Overflow

Risk 89
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Debian Debian LinuxThunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution contex…

Risk 39
Severity
6.5
First published (updated )

Mozilla ThunderbirdThunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527…

Risk 88
Severity
9.8
First published (updated )

Debian Debian LinuxThunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM co…

Risk 36
Severity
5.9
First published (updated )

Mozilla ThunderbirdOpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were s…

Risk 23
Severity
4.3
First published (updated )

Mozilla ThunderbirdIf a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contai…

Risk 23
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdRace Condition

Risk 15
Severity
2.5
First published (updated )

Mozilla ThunderbirdThunderbird did not check if the user ID associated with an OpenPGP key has a valid self signature. …

Risk 23
Severity
4.3
First published (updated )

Mozilla ThunderbirdWhen loading the shared library that provides the OTR protocol implementation, Thunderbird will init…

Risk 70
Severity
7.8
First published (updated )

Mozilla ThunderbirdIf a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validi…

Risk 53
Severity
6.8
First published (updated )

Mozilla ThunderbirdAn attacker may perform a DoS attack to prevent a user from sending encrypted email to a corresponde…

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Mozilla ThunderbirdThunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key impor…

Risk 45
Severity
7.5
First published (updated )

Mozilla ThunderbirdCommand Injection

Risk 79
Severity
8.8
First published (updated )

Mozilla ThunderbirdWhen reading SMTP server status codes, Thunderbird writes an integer value to a position on the stac…

Risk 82
Severity
9.3
First published (updated )

Mozilla ThunderbirdIf an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the…

Risk 36
Severity
5.9
First published (updated )

Canonical Ubuntu LinuxLast updated 25 August 2025

Risk 45
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203