CVE-2024-8394: Mozilla Thunderbird
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
When aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 128.2.
Affected products
- Mozilla Thunderbird: before 128.2.0 (fixed in 128.2.0)
Published 2024-09-06. Last modified 2026-06-17.