9.1
CVE-2026-84639
- EPSS 0.34%
- Veröffentlicht 01.09.2026 21:33:06
- Zuletzt bearbeitet 03.09.2026 19:01:50
- Erkennungen
Uninitialized memory in MIME parsing
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Thunderbird Version < 140.15.0
Mozilla ≫ Thunderbird Version >= 141.0 < 153.2.0
Mozilla ≫ Thunderbird Version >= 154.0 < 155.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.34% | 0.272 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
|
CWE-457 Use of Uninitialized Variable
The code uses a variable that has not been initialized, leading to unpredictable or unintended results.
https://bugzilla.mozilla.org/show_bug.cgi?id=2061087
https://www.mozilla.org/security/advisories/mfsa2026-86/
https://www.mozilla.org/security/advisories/mfsa2026-88/
https://www.mozilla.org/security/advisories/mfsa2026-87/