Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6483-1 | thunderbird security update |
Thu, 03 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
Wed, 02 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-457 | |
| Metrics |
cvssV3_1
|
Wed, 02 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mozilla
Mozilla thunderbird |
|
| Vendors & Products |
Mozilla
Mozilla thunderbird |
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| Title | Uninitialized memory in MIME parsing | |
| References |
|
Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2026-09-02T18:48:58.879Z
Reserved: 2026-09-01T21:33:05.937Z
Link: CVE-2026-84639
No data.
Status : Analyzed
Published: 2026-09-01T22:17:19.700
Modified: 2026-09-03T19:01:50.133
Link: CVE-2026-84639
No data.
OpenCVE Enrichment
Updated: 2026-09-03T11:45:03Z
Debian DSA