An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 30 Sep 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157. | An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4. |
| References |
|
Wed, 30 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157. | |
| Title | Heap buffer overflow opening large email | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-09-30T17:19:56.134Z
Reserved: 2026-09-30T17:15:06.146Z
Link: CVE-2026-103500
No data.
Status : Received
Published: 2026-09-30T18:18:18.120
Modified: 2026-09-30T18:18:18.120
Link: CVE-2026-103500
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.