Vulnerabilities
Vulnerable Software
A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVSS Score
9.8
EPSS Score
0.006
Published
2026-09-15
A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVSS Score
8.1
EPSS Score
0.005
Published
2026-09-15
A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
CVSS Score
9.1
EPSS Score
0.007
Published
2026-09-15


Contact Us

Shodan ® - All rights reserved