CVE-2020-26970
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable. This vulnerability affects Thunderbird < 78.5.1.
- Affected products
- Alt Linux, Centos, Red Hat, Thunderbird, Ubuntu
- Mozilla Thunderbird
- < 78.5.1
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2020-12-09
CVE-2020-26970 at NVD
No indexed exploits for CVE-2020-26970 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-26970 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.