Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4p49-pghr-968w

Опубликовано: 24 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

EPSS

Процентиль: 18%
0.00056
Низкий

7.4 High

CVSS3

Дефекты

CWE-126

Связанные уязвимости

CVSS3: 7.4
ubuntu
14 дней назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

CVSS3: 8.2
redhat
14 дней назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

CVSS3: 7.4
nvd
14 дней назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

CVSS3: 7.4
debian
14 дней назад

A malicious mail server could send malformed strings with negative len ...

oracle-oval
7 дней назад

ELSA-2026-6342: thunderbird security update (IMPORTANT)

EPSS

Процентиль: 18%
0.00056
Низкий

7.4 High

CVSS3

Дефекты

CWE-126