Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.
Multiple security issues were discovered in Thunderbird. If a user were tricked in to opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass the CSS sanitizer, or execute arbitrary code. (CVE-2020-16042,CVE-2020-16044,CVE-2020-26971, CVE-2020-26973,CVE-2020-26974,CVE-2020-26978,CVE-2020-35113)
It was discovered that the proxy.onRequest API did not catch view-source URLs. If a user were tricked in to installing an extension with the proxy permission and opening View Source, an attacker could potentially exploit this to obtain sensitive information. (CVE-2020-35111)
A stack overflow was discovered due to incorrect parsing of SMTP server response codes. An attacker could potentially exploit this to execute arbitrary code. (CVE-2020-26970)