CVE-2020-6795: Mozilla Thunderbird

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leading to an unexploitable crash. This vulnerability affects Thunderbird < 68.5.

Affected products

  • Mozilla Thunderbird: before 68.5.0 (fixed in 68.5.0)

Published 2020-03-02. Last modified 2026-06-17.