BlackTreeCVE IntelligenceOfficial source evidencewww.mozilla.orgVersioned article
Official source article · www.mozilla.org
Security Vulnerabilities fixed in Thunderbird 140.15 — Mozilla
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherwww.mozilla.org
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs14
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-84639Uninitialized memory in MIME parsing
- CVE-2026-84143Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- CVE-2026-84640One byte overflow read in mail parser
- CVE-2026-84641Information disclosure due to malicious IMAP server response
- CVE-2026-84145Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
- CVE-2026-84121Sandbox escape due to use-after-free in the DOM: Security component
- CVE-2026-84119Sandbox escape due to use-after-free in the DOM: Navigation component
- CVE-2026-84131Privilege escalation due to invalid pointer in the Graphics component
- CVE-2026-84124Use-after-free in the DOM: Core & HTML component
- CVE-2026-84122Use-after-free in the Audio/Video component
- CVE-2026-16371Privilege escalation in the DOM: Navigation component
- CVE-2026-16365Privilege escalation in the DOM: Workers component
- CVE-2026-84120Use-after-free in the Audio/Video component
- CVE-2026-75874Sandbox escape in the Remote Settings Client component
Source and provenance
Original title: Security Vulnerabilities fixed in Thunderbird 140.15 — Mozilla. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗