Skip to main content

Threats Tagged 'cve-2026-92240'

View all threats tagged with 'cve-2026-92240'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-92240

Threats Tagged 'cve-2026-92240'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-92240 is an out-of-bounds read vulnerability in the IMAP response parser of Thunderbird. A malicious or compromised IMAP server can send an untagged '* ID' response that triggers this vulnerability, causing Thunderbird to crash. This parsing path is reachable before user authentication. The issue was fixed in Thunderbird versions 156 and 140.16. Exploitation through email is generally not possible because scripting is disabled when reading mail in Thunderbird, but risks may exist in browser or browser-like contexts.

Join the discussion
0

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156 and Thunderbird 140.16.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-92240
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses