CVE-2024-8394: Mozilla Thunderbird

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.

Affected products

  • Mozilla Thunderbird: before 128.2.0 (fixed in 128.2.0)

Published 2024-09-06. Last modified 2026-06-17.