Description
Multiple vulnerabilities were found in Mozilla Thunderbird ESR. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information.
Below is a complete list of vulnerabilities:
- Denial of service vulnerability in MIME parsing can be exploited remotely to cause denial of service.
- Security vulnerability can be exploited to bypass security restrictions.
- Information disclosure vulnerability can be exploited to obtain sensitive information.
- Security vulnerability in the Remote Settings Client component can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Workers component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the DOM: Navigation component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the Audio/Video component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: Security component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: Core & HTML component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the DOM: Navigation component can be exploited to bypass security restrictions.
- Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
Original advisories
Exploitation
Related products
CVE list
- CVE-2026-16365 critical
- CVE-2026-16371 critical
- CVE-2026-75874 critical
- CVE-2026-84119 critical
- CVE-2026-84120 high
- CVE-2026-84121 critical
- CVE-2026-84122 high
- CVE-2026-84124 high
- CVE-2026-84131 critical
- CVE-2026-84143 unknown
- CVE-2026-84145 critical
- CVE-2026-84639 unknown
- CVE-2026-84640 unknown
- CVE-2026-84641 unknown
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!