Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
3ee3f21f by Salvatore Bonaccorso at 2026-07-22T07:36:06+02:00
Track fixes for firefox-esr via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -432,16 +432,16 @@ CVE-2026-15226 (A sandbox confinement bypass
vulnerability exists in Canonical s
[trixie] - snapd <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/21/1
CVE-2026-16361 (Memory safety bugs present in Firefox ESR 115.37 and Firefox
ESR 140.1 ...)
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR
140.12 a ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox
152. Some ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
CVE-2026-16411 (Memory safety bugs present in Firefox 152. Some of these bugs
showed e ...)
@@ -464,7 +464,7 @@ CVE-2026-16406 (Mitigation bypass in the Networking
component. This vulnerabilit
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16406
CVE-2026-16405 (Information disclosure in the Networking: WebSockets
component. This v ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16405
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16405
CVE-2026-16404 (Spoofing issue in Firefox for Android. This vulnerability was
fixed in ...)
@@ -493,7 +493,7 @@ CVE-2026-16397 (Clickjacking issue in the WebExtensions
component in Firefox for
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16397
CVE-2026-16396 (Privilege escalation in WebExtensions. This vulnerability was
fixed in ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16396
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16396
CVE-2026-16395 (Integer overflow in the Audio/Video component. This
vulnerability was ...)
@@ -504,7 +504,7 @@ CVE-2026-16394 (Mitigation bypass in the DOM: Security
component. This vulnerabi
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16394
CVE-2026-16359 (Incorrect boundary conditions in the Audio/Video: GMP
component. This ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16359
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16359
CVE-2026-16393 (Incorrect boundary conditions in the Graphics: WebGPU
component. This ...)
@@ -515,12 +515,12 @@ CVE-2026-16392 (JIT miscompilation in the JavaScript
Engine: JIT component. This
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16392
CVE-2026-16391 (Information disclosure in the Storage: IndexedDB component.
This vulne ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16391
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16391
CVE-2026-16390 (Mitigation bypass in the Enterprise Policies component. This
vulnerabi ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16390
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16390
CVE-2026-16389 (Incorrect boundary conditions, integer overflow in the
Libraries compo ...)
@@ -532,7 +532,7 @@ CVE-2026-16388 (Sandbox escape in the DOM: Networking
component. This vulnerabil
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16388
CVE-2026-16387 (Site isolation issue in the Networking component. This
vulnerability w ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16387
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16387
CVE-2026-16386 (Information disclosure due to uninitialized memory in the
Graphics: We ...)
@@ -546,7 +546,7 @@ CVE-2026-16384 (Information disclosure due to uninitialized
memory in the Graphi
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16384
CVE-2026-16383 (Mitigation bypass in the DOM: Networking component. This
vulnerability ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16383
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16383
CVE-2026-16382 (Mitigation bypass in the DOM: Service Workers component. This
vulnerab ...)
@@ -554,7 +554,7 @@ CVE-2026-16382 (Mitigation bypass in the DOM: Service
Workers component. This vu
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16382
CVE-2026-16381 (Same-origin policy bypass in the Networking: DNS component.
This vulne ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16381
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16381
CVE-2026-16380 (Mitigation bypass in the Networking component. This
vulnerability was ...)
@@ -562,12 +562,12 @@ CVE-2026-16380 (Mitigation bypass in the Networking
component. This vulnerabilit
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16380
CVE-2026-16358 (Site isolation issue in the Graphics: WebRender component.
This vulner ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16358
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16358
CVE-2026-16379 (Privilege escalation in the DOM: Content Processes component.
This vul ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16379
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16379
CVE-2026-16378 (Other issue in the DOM: Copy & Paste and Drag & Drop
component. This v ...)
@@ -575,7 +575,7 @@ CVE-2026-16378 (Other issue in the DOM: Copy & Paste and
Drag & Drop component.
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16378
CVE-2026-16377 (Mitigation bypass in the PDF Viewer component. This
vulnerability was ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16377
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16377
CVE-2026-16376 (Denial-of-service in the Graphics: WebGPU component. This
vulnerabilit ...)
@@ -583,12 +583,12 @@ CVE-2026-16376 (Denial-of-service in the Graphics: WebGPU
component. This vulner
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16376
CVE-2026-16375 (Site isolation issue in the Networking: HTTP component. This
vulnerabi ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16375
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16375
CVE-2026-16374 (Information disclosure in the Framework component in DevTools.
This vu ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16374
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16374
CVE-2026-16373 (Information disclosure in the Privacy component in Firefox for
Android ...)
@@ -599,7 +599,7 @@ CVE-2026-16372 (Privilege escalation in the DOM: Content
Processes component. Th
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16372
CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This
vulnerabil ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16371
CVE-2026-16370 (Mitigation bypass in the DOM: Networking component. This
vulnerability ...)
@@ -607,27 +607,27 @@ CVE-2026-16370 (Mitigation bypass in the DOM: Networking
component. This vulnera
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16370
CVE-2026-16357 (Incorrect boundary conditions in the Graphics component. This
vulnerab ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16357
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16357
CVE-2026-16356 (Sandbox escape due to use-after-free in the Disability Access
APIs com ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16356
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16356
CVE-2026-16355 (JIT miscompilation in the JavaScript Engine: JIT component.
This vulne ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16355
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16355
CVE-2026-16369 (Integer overflow in the JavaScript: WebAssembly component.
This vulner ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16369
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16369
CVE-2026-16368 (Incorrect boundary conditions in the JavaScript: WebAssembly
component ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16368
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16368
CVE-2026-16367 (Sandbox escape due to invalid pointer in the Disability Access
APIs co ...)
@@ -635,12 +635,12 @@ CVE-2026-16367 (Sandbox escape due to invalid pointer in
the Disability Access A
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
CVE-2026-16354 (Information disclosure in the Graphics: ImageLib component.
This vulne ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16354
CVE-2026-16353 (Invalid pointer in the DOM: Bindings (WebIDL) component. This
vulnerab ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16353
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16353
CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This
vulnerabil ...)
@@ -654,32 +654,32 @@ CVE-2026-16364 (Incorrect boundary conditions in the
Audio/Video: Playback compo
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16364
CVE-2026-16363 (JIT miscompilation in the JavaScript: WebAssembly component.
This vuln ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16363
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16363
CVE-2026-16352 (Sandbox escape due to use-after-free in the Disability Access
APIs com ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16352
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16352
CVE-2026-16351 (Sandbox escape due to use-after-free in the DOM: Navigation
component. ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16351
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16351
CVE-2026-16362 (Use-after-free in the WebRTC: Audio/Video component. This
vulnerabilit ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16362
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16362
CVE-2026-16350 (Incorrect boundary conditions in the Audio/Video: cubeb
component. Thi ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16350
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16350
CVE-2026-16349 (Same-origin policy bypass in the DOM: Navigation component.
This vulne ...)
- firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16349
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16349
CVE-2026-15370 (A flaw was found in libssh. During SFTP server directory
listing, the ...)
@@ -7946,12 +7946,12 @@ CVE-2024-7708 (For requests that have a body, but
reading the body may end up in
TODO: check
CVE-2026-15719 (We are aware that exploit code for this is public however we
are not a ...)
- firefox 152.0.6-1
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15719
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-15719
CVE-2026-15718 (We are aware that exploit code for this is public however we
are not a ...)
- firefox 152.0.6-1
- - firefox-esr <unfixed>
+ - firefox-esr 140.13.0esr-1
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15718
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-15718
CVE-2026-42491
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ee3f21f502a6ad4e7f0cde2ef17b9705685c434
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3ee3f21f502a6ad4e7f0cde2ef17b9705685c434
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits