Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Several Reporters

#47870of 53,608
5.3Total CVSS
Vulnerabilities · 1
PT-2024-9993
5.3
2024-11-12
Mozilla · Thunderbird · CVE-2024-11159
Name of the Vulnerable Software and Affected Versions: Thunderbird versions prior to 128.4.3 Thunderbird versions prior to 132.0.1 Description: The issue is related to the use of remote content in OpenPGP encrypted messages, which can lead to the disclosure of plaintext. This is due to insufficient protection of service data in the implementation of the OpenPGP email encryption standard in the Mozilla Thunderbird email client. An attacker can exploit this vulnerability to reveal protected information. Recommendations: For Thunderbird versions prior to 128.4.3, update to version 128.4.3 or later. For Thunderbird versions prior to 132.0.1, update to version 132.0.1 or later. As a temporary workaround, consider avoiding the use of remote content in OpenPGP encrypted messages until a patch is available.