Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4p49-pghr-968w

Опубликовано: 24 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

EPSS

Процентиль: 30%
0.0036
Низкий

7.4 High

CVSS3

Дефекты

CWE-126
CWE-130

Связанные уязвимости

CVSS3: 7.4
ubuntu
6 месяцев назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

CVSS3: 8.2
redhat
6 месяцев назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

CVSS3: 7.4
nvd
6 месяцев назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

CVSS3: 7.4
debian
6 месяцев назад

A malicious mail server could send malformed strings with negative len ...

CVSS3: 7.4
fstec
6 месяцев назад

Уязвимость почтового клиента Thunderbird, связанная с чтением за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 30%
0.0036
Низкий

7.4 High

CVSS3

Дефекты

CWE-126
CWE-130