Mozilla Thunderbird
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*
- < 136
- < 128.8
A vulnerability exists in Mozilla Thunderbird versions prior to 136 and prior to 128.8, where an incorrect padding size was used when requesting OpenPGP keys from a WKD server. This flaw allowed a network observer to infer the length of the email address being requested.
Exploitation of this vulnerability could lead to the disclosure of the length of the requested email address to a network observer.
Users can upgrade to Thunderbird 136 or Thunderbird 128.8 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.