Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4p49-pghr-968w

Опубликовано: 24 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

EPSS

Процентиль: 28%
0.0036
Низкий

7.4 High

CVSS3

Дефекты

CWE-126
CWE-130

Связанные уязвимости

CVSS3: 7.4
ubuntu
4 месяца назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

CVSS3: 8.2
redhat
4 месяца назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

CVSS3: 7.4
nvd
4 месяца назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.

CVSS3: 7.4
debian
4 месяца назад

A malicious mail server could send malformed strings with negative len ...

rocky
4 месяца назад

Important: thunderbird security update

EPSS

Процентиль: 28%
0.0036
Низкий

7.4 High

CVSS3

Дефекты

CWE-126
CWE-130