Buffer Overflow Vulnerability in Thunderbird by Mozilla
CVE-2026-84640

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84640?

An issue in Thunderbird allows a maliciously crafted mail header to cause a buffer overflow. This could lead to unauthorized memory access, potentially allowing attackers to read past the end of a buffer. The vulnerability has been addressed in versions 155, 140.15, and 153.2, enhancing the security of the email client.

Affected Version(s)

Thunderbird 140.15

Thunderbird 153.2

Thunderbird 155

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ramesh Adhikari, Dr. Faruk Kazi (CoE-CNDS Lab, VJTI, Mumbai, India)
.