CVE-2026-57962
בינונית 5.3
תיאור (מקור, אנגלית)
A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-15/8/2026
- CWE
- CWE-400
מוצרים מושפעים
mozilla: thunderbird
קישורים
- https://www.mozilla.org/security/advisories/mfsa2026-63/ Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2026-64/ Vendor Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=2042872 Permissions Required