Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-4371

Опубликовано: 24 мар. 2026
Источник: nvd
CVSS3: 7.4
EPSS Низкий

Описание

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
Версия до 140.9.0 (исключая)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
Версия до 149.0 (исключая)

EPSS

Процентиль: 18%
0.00056
Низкий

7.4 High

CVSS3

Дефекты

CWE-126

Связанные уязвимости

CVSS3: 7.4
ubuntu
14 дней назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

CVSS3: 8.2
redhat
14 дней назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

CVSS3: 7.4
debian
14 дней назад

A malicious mail server could send malformed strings with negative len ...

CVSS3: 7.4
github
14 дней назад

A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.

oracle-oval
7 дней назад

ELSA-2026-6342: thunderbird security update (IMPORTANT)

EPSS

Процентиль: 18%
0.00056
Низкий

7.4 High

CVSS3

Дефекты

CWE-126