GHSA-2q8r-2ghc-82v8HighCVSS 7.5
A maliciously constructed mail header could lead to a one byte read past the end of a buffer....
🔗 CVE IDs covered (1)
📋 Description
A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-84640
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063964
- https://www.mozilla.org/security/advisories/mfsa2026-86
- https://www.mozilla.org/security/advisories/mfsa2026-87
- https://www.mozilla.org/security/advisories/mfsa2026-88
- https://github.com/advisories/GHSA-2q8r-2ghc-82v8