CVE-2026-4371
EUVD-2026-1502324.03.2026, 21:16
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability affects Thunderbird < 149 and Thunderbird < 140.9.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mozilla | thunderbird_esr | 𝑥 < 140.9.0 |
| mozilla | thunderbird | 𝑥 < 149.0 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration