Impact
An attacker can trigger a heap buffer overflow by sending a user an email that is at least 2GB in size. If the victim opens the message, the overflow may corrupt memory and can lead to arbitrary code execution or a crash, compromising confidentiality or integrity of the client process. The vulnerability is a heap-based buffer overflow.
Affected Systems
The flaw affects Mozilla Thunderbird; versions prior to Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4 are vulnerable, with the issue fixed in those releases.
Risk and Exploitability
The CVSS score is not available and the EPSS score is not provided, and the vulnerability is not listed in CISA KEV. Exploitation requires the victim to open an email that exceeds 2GB, so the likely attack vector is a social‑engineering campaign that tricks a user into opening a large attachment. If successfully exploited, it could cause the client to crash or run arbitrary code, depending on the local privilege of the user.
OpenCVE Enrichment