← back
CVE-2026-103500

Heap buffer overflow opening large email

0Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Track
exploitation probability
—
observed exploitation
nono source reports it
An attacker could cause a heap buffer overflow by getting a user to open an email that is greater than or equal to 2GB in size. This vulnerability was fixed in Thunderbird 157, Thunderbird 140.17, and Thunderbird 153.4.
Affected products
Mozilla · Thunderbird