CVE-2018-18513: Mozilla Thunderbird

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-of-service (DOS) attack because Thunderbird reopens the last seen message on restart, triggering the crash again. This vulnerability affects Thunderbird < 60.5.

Affected products

  • Mozilla Thunderbird: before 60.5.0 (fixed in 60.5.0)

Published 2019-04-26. Last modified 2026-06-17.