CVE-2020-26970

HIGH

Thunderbird <78.5.1 - Buffer Overflow

Title source: llm
STIX 2.1

Description

When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable. This vulnerability affects Thunderbird < 78.5.1.

References (2)

Core 2
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1677338
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2020-53/

Scores

CVSS v3 8.8
EPSS 0.0038
EPSS Percentile 59.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
mozilla/thunderbird < 78.5.1
Published Dec 09, 2020
Tracked Since Feb 18, 2026