CVE-2019-11705 describes a critical stack buffer overflow vulnerability in Mozilla Thunderbird versions prior to 60.7.1. This flaw occurs when processing specially crafted iCal email messages, leading to a potentially exploitable crash. With a CVSS score of 9.8, this vulnerability is highly severe, allowing unauthenticated attackers to achieve complete compromise (confidentiality, integrity, availability) with low attack complexity. While not listed on CISA's KEV catalog, public exploit code exists, and it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 60.7.1CPE match | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.