Description
Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code, obtain sensitive information.
Below is a complete list of vulnerabilities:
- Security vulnerability can be exploited to bypass security restrictions.
- Denial of service vulnerability in IMAP response parser can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in the Audio/Video: Web Codecs component can be exploited remotely to execute arbitrary code.
- Denial of service vulnerability in the Graphics: CanvasWebGL component can be exploited remotely to cause denial of service.
- Denial of service vulnerability in the Graphics component can be exploited remotely to cause denial of service.
- Security vulnerability in the WebExtensions component can be exploited to bypass security restrictions.
- A remote code execution vulnerability in the Disability Access APIs component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the DOM: Service Workers component can be exploited to bypass security restrictions.
- Security vulnerability in the DOM: Core & HTML component can be exploited to bypass security restrictions.
- Security vulnerability in the Remote Settings Client component can be exploited to bypass security restrictions.
- Denial of service vulnerability in the Graphics: WebRender component can be exploited remotely to cause denial of service.
- A remote code execution vulnerability in the JavaScript Engine: JIT component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: HTML Parser component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the XML component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the SVG component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: Navigation component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the Networking component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: Streams component can be exploited remotely to execute arbitrary code.
- A remote code execution vulnerability in the DOM: Core & HTML component can be exploited remotely to execute arbitrary code.
- Security vulnerability in the DOM: Copy & Paste and Drag & Drop component can be exploited to bypass security restrictions.
- Information disclosure vulnerability in the Graphics: ImageLib component can be exploited to obtain sensitive information.
Original advisories
Exploitation
Public exploits exist for this vulnerability.
Related products
CVE list
- CVE-2026-92005 high
- CVE-2026-92006 critical
- CVE-2026-92007 critical
- CVE-2026-92008 critical
- CVE-2026-92009 critical
- CVE-2026-92010 critical
- CVE-2026-92011 critical
- CVE-2026-92012 critical
- CVE-2026-92013 critical
- CVE-2026-92014 critical
- CVE-2026-92015 critical
- CVE-2026-92016 critical
- CVE-2026-92017 critical
- CVE-2026-92018 critical
- CVE-2026-92019 unknown
- CVE-2026-92020 critical
- CVE-2026-92021 critical
- CVE-2026-92022 critical
- CVE-2026-92023 critical
- CVE-2026-92024 critical
- CVE-2026-92025 critical
- CVE-2026-92026 critical
- CVE-2026-92027 critical
- CVE-2026-92028 critical
- CVE-2026-92029 critical
- CVE-2026-92030 unknown
- CVE-2026-92031 unknown
- CVE-2026-92032 unknown
- CVE-2026-92238 unknown
- CVE-2026-92239 unknown
- CVE-2026-92240 unknown
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!