Description
Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
Published: 2026-06-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves a memory safety bug that can result in buffer overflows, use‑after‑free conditions, or null pointer dereferences. This can corrupt application memory, potentially causing crashes or providing a foothold for malicious code if the flaw is successfully leveraged.

Affected Systems

Mozilla Firefox (Extended Support Release) prior to version 140.12 and Mozilla Thunderbird (Extended Support Release) prior to version 140.12 are affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. With an EPSS score below 1% and no listing in CISA KEV, exploitation is currently unlikely. Nevertheless, the flaw could be triggered by maliciously crafted email content or attachments, making the vector likely local or remote delivery of corrupted data. Successful exploitation would depend on an attacker’s ability to get the target to process the harmful input.

Generated by OpenCVE AI on June 17, 2026 at 21:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox ESR to version 140.12 or later.
  • Upgrade Thunderbird ESR to version 140.12 or later.
  • If an upgrade is not immediately possible, restrict the processing of potentially malformed email attachments and remain vigilant for abnormal crashes.

Generated by OpenCVE AI on June 17, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4635-1 firefox-esr security update
Debian DLA Debian DLA DLA-4636-1 thunderbird security update
Debian DSA Debian DSA DSA-6350-1 firefox-esr security update
Debian DSA Debian DSA DSA-6351-1 thunderbird security update
References
Link Providers
https://access.redhat.com/errata/RHSA-2026:27717 cve-icon
https://access.redhat.com/errata/RHSA-2026:27733 cve-icon
https://access.redhat.com/errata/RHSA-2026:27734 cve-icon
https://access.redhat.com/errata/RHSA-2026:29940 cve-icon
https://access.redhat.com/errata/RHSA-2026:30846 cve-icon
https://access.redhat.com/errata/RHSA-2026:33445 cve-icon
https://access.redhat.com/errata/RHSA-2026:36100 cve-icon
https://access.redhat.com/errata/RHSA-2026:36101 cve-icon
https://access.redhat.com/errata/RHSA-2026:36102 cve-icon
https://access.redhat.com/errata/RHSA-2026:36103 cve-icon
https://access.redhat.com/errata/RHSA-2026:37210 cve-icon
https://access.redhat.com/errata/RHSA-2026:37391 cve-icon
https://access.redhat.com/errata/RHSA-2026:38506 cve-icon
https://access.redhat.com/errata/RHSA-2026:38750 cve-icon
https://access.redhat.com/errata/RHSA-2026:38751 cve-icon
https://access.redhat.com/errata/RHSA-2026:38753 cve-icon
https://access.redhat.com/errata/RHSA-2026:39011 cve-icon
https://access.redhat.com/errata/RHSA-2026:39141 cve-icon
https://access.redhat.com/errata/RHSA-2026:39142 cve-icon
https://access.redhat.com/errata/RHSA-2026:39428 cve-icon
https://access.redhat.com/errata/RHSA-2026:39706 cve-icon
https://access.redhat.com/security/cve/CVE-2026-12329 cve-icon
https://bugzilla.mozilla.org/show_bug.cgi?id=2044738 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2489214 cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-12329 cve-icon
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12329.json cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-12329 cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-58/ cve-icon cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-58/#CVE-2026-12329 cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-61/ cve-icon cve-icon
https://www.mozilla.org/security/advisories/mfsa2026-61/#CVE-2026-12329 cve-icon
History

Thu, 18 Jun 2026 16:45:00 +0000


Tue, 16 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
Vendors & Products Mozilla thunderbird

Tue, 16 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Description Memory safety bug fixed in Firefox ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12. Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
Title Memory safety bug fixed in Firefox ESR 140.12 Memory safety bug fixed in Thunderbird ESR 140.12
References

Tue, 16 Jun 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-416
CWE-476
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 16 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
Description Memory safety bug fixed in Firefox ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12.
Title Memory safety bug fixed in Firefox ESR 140.12
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-15T11:48:33.741Z

Reserved: 2026-06-15T15:08:22.406Z

Link: CVE-2026-12329

cve-icon Vulnrichment

Updated: 2026-07-15T11:48:33.741Z

cve-icon NVD

Status : Modified

Published: 2026-06-16T13:16:33.657

Modified: 2026-07-15T12:17:07.810

Link: CVE-2026-12329

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-16T11:53:02Z

Links: CVE-2026-12329 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T21:45:02Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free

  • CWE-476

    NULL Pointer Dereference