Vulnerability Details CVE-2026-12329
Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 16.2%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2026-12329
-
cpe:2.3:a:mozilla:firefox:140.0
-
cpe:2.3:a:mozilla:firefox:140.1.0
-
cpe:2.3:a:mozilla:firefox:140.10.0
-
cpe:2.3:a:mozilla:firefox:140.10.1
-
cpe:2.3:a:mozilla:firefox:140.10.2
-
cpe:2.3:a:mozilla:firefox:140.11.0
-
cpe:2.3:a:mozilla:firefox:140.2.0
-
cpe:2.3:a:mozilla:firefox:140.3
-
cpe:2.3:a:mozilla:firefox:140.3.0
-
cpe:2.3:a:mozilla:firefox:140.3.1
-
cpe:2.3:a:mozilla:firefox:140.4.0
-
cpe:2.3:a:mozilla:firefox:140.5.0
-
cpe:2.3:a:mozilla:firefox:140.6.0
-
cpe:2.3:a:mozilla:firefox:140.7.0
-
cpe:2.3:a:mozilla:firefox:140.7.1
-
cpe:2.3:a:mozilla:firefox:140.8.0
-
cpe:2.3:a:mozilla:firefox:140.9.0
-
cpe:2.3:a:mozilla:firefox:140.9.1
-
cpe:2.3:a:mozilla:thunderbird:140.0
-
cpe:2.3:a:mozilla:thunderbird:140.0.1
-
cpe:2.3:a:mozilla:thunderbird:140.1.0
-
cpe:2.3:a:mozilla:thunderbird:140.1.1
-
cpe:2.3:a:mozilla:thunderbird:140.2.0
-
cpe:2.3:a:mozilla:thunderbird:140.2.1
-
cpe:2.3:a:mozilla:thunderbird:140.3.0
-
cpe:2.3:a:mozilla:thunderbird:140.3.1
-
cpe:2.3:a:mozilla:thunderbird:140.4.0
-
cpe:2.3:a:mozilla:thunderbird:140.5.0
-
cpe:2.3:a:mozilla:thunderbird:140.6.0
-
cpe:2.3:a:mozilla:thunderbird:140.7.0