EUVD Vulnerability Catalog
EUVD-2026-69708
Severity: CRITICAL
Base Score: 9.1
CVSS Version: 3.1
Vulnerability Description
Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
▪
Attack Vector (AV): Network
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): None
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): None
▪
Availability Impact (A): High
References & Advisory Links
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
mozilla
EPSS Probability
0
Known Aliases
CVE-2026-84639
GHSA-4x6j-cpvp-7f2c
Published On
2026-09-01
Last Updated
2026-09-02