Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
837f9c46 by Salvatore Bonaccorso at 2026-08-18T22:49:57+02:00
Add thunderbird issues from mfsa2026-79
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -121,8 +121,10 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient
validation of packet len
CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13,
Thunderbird E ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74990
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74990
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74990
CVE-2026-74989 (Internally found bugs present in Thunderbird 153. Some of
these bugs s ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74989
@@ -132,8 +134,10 @@ CVE-2026-74988 (Internally found bugs present in
Thunderbird ESR 153.0 and Thund
CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13,
Thunderbird E ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74987
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74987
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74987
CVE-2026-74986 (Site isolation issue in the CSS Parsing and Computation
component. Thi ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74986
@@ -146,8 +150,10 @@ CVE-2026-74984 (Race condition in the JavaScript Engine
component. This vulnerab
CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This
vulnerab ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74983
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74983
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74983
CVE-2026-74982 (Denial-of-service in the Widget component. This vulnerability
was fixe ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74982
@@ -169,91 +175,119 @@ CVE-2026-74977 (Integer overflow in the Graphics
component. This vulnerability w
CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component.
This vulne ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74976
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74976
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74976
CVE-2026-74975 (Spoofing issue in the Downloads component in Firefox for
Android. This ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component.
This vu ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74974
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This
vulnera ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74973
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions
component. This ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74972
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling
componen ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74971
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74971
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74971
CVE-2026-74970 (Site isolation issue in the Graphics component. This
vulnerability was ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This
vulnerabi ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74969
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74969
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74969
CVE-2026-74968 (Site isolation issue in the Graphics: WebRender component.
This vulner ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback
component. This ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74967
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74967
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74967
CVE-2026-74966 (Information disclosure in the Form Autofill component. This
vulnerabil ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
CVE-2026-74965 (Privilege escalation in the Shell Integration component. This
vulnerab ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74965
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability
was fix ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74964
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies
component. This v ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74963
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
CVE-2026-74962 (Site isolation issue in the Networking: Cookies component.
This vulner ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74962
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74962
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74962
CVE-2026-74961 (Side-channel in the Web Audio component. This vulnerability
was fixed ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
CVE-2026-74960 (Site isolation issue in the WebExtensions component. This
vulnerabilit ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74960
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This
vulnerabil ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74959
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74959
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74959
CVE-2026-74958 (Information disclosure in the WebRTC component. This
vulnerability was ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This
vulnerability w ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74957
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74957
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74957
CVE-2026-74956 (Same-origin policy bypass in the DOM: Service Workers
component. This ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74956
@@ -266,8 +300,10 @@ CVE-2026-74954 (Information disclosure due to side-channel
in the Storage: Cache
CVE-2026-74953 (Privilege escalation in the Networking: Cookies component.
This vulner ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74953
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74953
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74953
CVE-2026-74952 (Privilege escalation in the Application Update component. This
vulnera ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74952
@@ -280,56 +316,76 @@ CVE-2026-74950 (Privilege escalation in the Downloads API
component. This vulner
CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics:
Canvas2D c ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74949
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
CVE-2026-74948 (Information disclosure in the Graphics component. This
vulnerability w ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74948
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74948
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74948
CVE-2026-74947 (Privilege escalation due to invalid pointer in the Graphics
component. ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in
the Graph ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74946
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
CVE-2026-74945 (Information disclosure in the Graphics: Text component. This
vulnerabi ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74945
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This
vulnerability w ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74944
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This
vulnerability ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74943
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
CVE-2026-74942 (Privilege escalation in the Remote Settings Client component.
This vul ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74942
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component.
This vuln ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74941
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
CVE-2026-74940 (Use-after-free in the Graphics: Text component. This
vulnerability was ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74940
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This
vulnerabil ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74939
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74939
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74939
CVE-2026-74938 (Mitigation bypass in the JavaScript: GC component. This
vulnerability ...)
- firefox <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74938
@@ -339,18 +395,24 @@ CVE-2026-74937 (Use-after-free in the JavaScript: GC
component. This vulnerabili
CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This
vulnerab ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74936
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This
vulnerabil ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74935
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component.
This vuln ...)
- firefox <unfixed>
- firefox-esr <unfixed>
+ - thunderbird <unfixed>
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74934
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74934
+ NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74934
CVE-2026-74908 (Grav plugin-api before 1.0.15 contains a script injection
vulnerabilit ...)
TODO: check
CVE-2026-74907 (Grav before 2.0.15 contains a path traversal vulnerability in
the stat ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/837f9c468d3cf728cda7b67b47b85ccdf2504e0c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/837f9c468d3cf728cda7b67b47b85ccdf2504e0c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits