Mozilla Thunderbird
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*
- < 149
- < 140.9
A vulnerability exists in Mozilla Thunderbird versions prior to 149 and versions prior to 140.9. This issue allows a malicious mail server to send improperly formatted strings with negative lengths, which can cause the email parser to read memory outside of its allocated buffer. Such exploitation could lead to a parser malfunction, potentially crashing Thunderbird or causing a leak of sensitive information.
Exploitation of this vulnerability could result in a crash of the Thunderbird application or unauthorized disclosure of sensitive data.
Users can upgrade to Thunderbird versions 149 or 140.9 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.