All apps
T

Thunderbird

Communication
Mozilla·Website

Free email, calendar, and chat client — release and ESR channels

Latest versions

Stable
WindowsmacOSLinux
155.0
Enterprise Stable
WindowsmacOSLinux
140.15.0esr
Actively exploited
0
CISA KEV · 14 lifetime
Affecting latest
0
v155.0
+14 unverified
Known CVEs
1914
across all versions, as matched by PemSync
Last checked
6 Sep 2026, 0:15

Of 1914 recorded CVEs, 1900 are fixed in versions you're past. 14 could not be evaluated against 155.0 — treat them as unknown rather than resolved. They are listed first in the table below.

These verdicts were computed against 155.0 only. We also track Enterprise Stable 140.15.0esr, which was not evaluated — a CVE fixed in 155.0 may still affect that build.

CVESeverityEPSS pctStatusScore source
95%Impact unverified4 Feb 2019
90%Impact unverified16 May 2018
92%Impact unverified16 May 2018
61%Impact unverified29 Jan 2010
81%Impact unverified17 Dec 2009
81%Impact unverified17 Dec 2009
90%Impact unverified17 Dec 2009
89%Impact unverified17 Dec 2009
89%Impact unverified17 Dec 2009
82%Impact unverified12 Jun 2009
70%Impact unverified22 Apr 2009
82%Impact unverified22 Apr 2009
81%Impact unverified22 Apr 2009
69%Impact unverified22 Apr 2009
CVE-2024-9680Exploited
CRITICAL 9.898%Latest not affectedNVD9 Oct 2024
CVE-2023-5217Exploited
HIGH 8.899%Latest not affectedNVD28 Sep 2023
CVE-2023-4863Exploited
HIGH 8.8100%Latest not affectedNVD12 Sep 2023
CRITICAL 9.683%Latest not affectedNVD22 Dec 2022
HIGH 8.896%Latest not affectedNVD22 Dec 2022
CVE-2020-6820Exploited
HIGH 8.194%Latest not affectedNVD24 Apr 2020
CVE-2020-6819Exploited
HIGH 8.186%Latest not affectedNVD24 Apr 2020
HIGH 8.899%Latest not affectedNVD2 Mar 2020
CRITICAL 10.099%Latest not affectedNVD23 Jul 2019
HIGH 8.898%Latest not affectedNVD23 Jul 2019
CVE-2016-9079Exploited
HIGH 7.5100%Latest not affectedNVD11 Jun 2018
Showing 125 of 1914
Page 1 of 77

PemSync reports known, cataloged exploited vulnerabilities (CISA KEV) and published CVEs. It is not a zero-day detection or threat-intelligence system — a vulnerability may be exploited before it appears here. Absence of data does not mean an app is secure.

More from Mozilla