CVE-2026-4371
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail
CVSS
7.4
Alto
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 24 mar 2026 · Última mod.: 15 jul 2026 · CWE-126 · CWE-130
0.4%EPSS · 30 días0.4%
2026-08-202026-09-17
A malicious mail server could send malformed strings with negative lengths, causing the parser to read memory outside the buffer. If a mail server or connection to a mail server were compromised, an attacker could cause the parser to malfunction, potentially crashing Thunderbird or leaking sensitive data. This vulnerability was fixed in Thunderbird 149 and Thunderbird 140.9.
- bugzilla.mozilla.orghttps://bugzilla.mozilla.org/show_bug.cgi?id=2023493
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-23/
- www.mozilla.orghttps://www.mozilla.org/security/advisories/mfsa2026-24/
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:6188
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:6342
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:6917
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:8284
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:8285
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:8286
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:8287
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:8288
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:8289
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:8290
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:8315
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:8850
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-4371
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2451001
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4371.json
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-252947.4 ALT5.2%
——2Transient DOS while parsing frame during channel usage.1dCVE-2026-252847.3 ALT1.3%
——0Information Disclosure when a pointer is reused after being deallocated.1dCVE-2026-252757.5 ALT22.7%
——7Transient DOS when processing authentication frames with invalid FILS information element header lengths.1dCVE-2026-240817.4 ALT5.2%
——2Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.1dCVE-2026-240757.8 ALT1.5%
——0Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.1dCVE-2026-734557.5 ALT40.1%
——12On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can cause the OSPFv3 agent to restart unexpectedly.2d