[Git][security-tracker-team/security-tracker][master] Track fixed versions via unstable for thunderbird issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 5 04:38:29 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d63977a6 by Salvatore Bonaccorso at 2026-08-05T05:37:59+02:00
Track fixed versions via unstable for thunderbird issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9865,7 +9865,7 @@ CVE-2026-16628 (A vulnerability was detected in oclif up to 4.23.16. Affected by
CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to reject dot ...)
NOT-FOR-US: fastify/static
CVE-2026-14899 (The code to parse MIME headers for display when forwarding a message ( ...)
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-14899
CVE-2026-14881 (When importing connections in Compass it is possible to override some ...)
NOT-FOR-US: mongodb-js (not same as node-mongodb)
@@ -13272,14 +13272,14 @@ CVE-2026-15226 (A sandbox confinement bypass vulnerability exists in Canonical s
CVE-2026-16361 (Memory safety bugs present in Thunderbird ESR 140.12. Some of these bu ...)
{DSA-6394-1 DLA-4695-1}
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16361
CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 a ...)
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16360
@@ -13287,7 +13287,7 @@ CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox 152
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16412
@@ -13313,7 +13313,7 @@ CVE-2026-16405 (Information disclosure in the Networking: WebSockets component.
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16405
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16405
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16405
@@ -13345,7 +13345,7 @@ CVE-2026-16396 (Privilege escalation in WebExtensions. This vulnerability was fi
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16396
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16396
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16396
@@ -13359,7 +13359,7 @@ CVE-2026-16359 (Incorrect boundary conditions in the Audio/Video: GMP component.
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16359
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16359
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16359
@@ -13373,7 +13373,7 @@ CVE-2026-16391 (Information disclosure in the Storage: IndexedDB component. This
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16391
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16391
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16391
@@ -13381,7 +13381,7 @@ CVE-2026-16390 (Mitigation bypass in the Enterprise Policies component. This vul
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16390
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16390
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16390
@@ -13398,7 +13398,7 @@ CVE-2026-16387 (Site isolation issue in the Networking component. This vulnerabi
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16387
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16387
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16387
@@ -13415,7 +13415,7 @@ CVE-2026-16383 (Mitigation bypass in the DOM: Networking component. This vulnera
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16383
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16383
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16383
@@ -13426,7 +13426,7 @@ CVE-2026-16381 (Same-origin policy bypass in the Networking: DNS component. This
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16381
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16381
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16381
@@ -13437,7 +13437,7 @@ CVE-2026-16358 (Site isolation issue in the Graphics: WebRender component. This
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16358
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16358
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16358
@@ -13445,7 +13445,7 @@ CVE-2026-16379 (Privilege escalation in the DOM: Content Processes component. Th
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16379
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16379
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16379
@@ -13456,7 +13456,7 @@ CVE-2026-16377 (Mitigation bypass in the PDF Viewer component. This vulnerabilit
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16377
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16377
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16377
@@ -13467,7 +13467,7 @@ CVE-2026-16375 (Site isolation issue in the Networking: HTTP component. This vul
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16375
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16375
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16375
@@ -13475,7 +13475,7 @@ CVE-2026-16374 (Information disclosure in the Framework component in DevTools. T
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16374
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16374
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16374
@@ -13489,7 +13489,7 @@ CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This vuln
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16371
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16371
@@ -13500,7 +13500,7 @@ CVE-2026-16357 (Incorrect boundary conditions in the Graphics component. This vu
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16357
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16357
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16357
@@ -13508,7 +13508,7 @@ CVE-2026-16356 (Sandbox escape due to use-after-free in the Disability Access AP
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16356
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16356
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16356
@@ -13516,7 +13516,7 @@ CVE-2026-16355 (JIT miscompilation in the JavaScript Engine: JIT component. This
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16355
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16355
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16355
@@ -13524,7 +13524,7 @@ CVE-2026-16369 (Integer overflow in the JavaScript: WebAssembly component. This
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16369
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16369
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16369
@@ -13532,7 +13532,7 @@ CVE-2026-16368 (Incorrect boundary conditions in the JavaScript: WebAssembly com
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16368
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16368
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16368
@@ -13543,7 +13543,7 @@ CVE-2026-16354 (Information disclosure in the Graphics: ImageLib component. This
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16354
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16354
@@ -13551,7 +13551,7 @@ CVE-2026-16353 (Invalid pointer in the DOM: Bindings (WebIDL) component. This vu
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16353
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16353
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16353
@@ -13568,7 +13568,7 @@ CVE-2026-16363 (JIT miscompilation in the JavaScript: WebAssembly component. Thi
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16363
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16363
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16363
@@ -13576,7 +13576,7 @@ CVE-2026-16352 (Sandbox escape due to use-after-free in the Disability Access AP
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16352
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16352
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16352
@@ -13584,7 +13584,7 @@ CVE-2026-16351 (Sandbox escape due to use-after-free in the DOM: Navigation comp
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16351
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16351
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16351
@@ -13592,7 +13592,7 @@ CVE-2026-16362 (Use-after-free in the WebRTC: Audio/Video component. This vulner
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16362
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16362
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16362
@@ -13600,7 +13600,7 @@ CVE-2026-16350 (Incorrect boundary conditions in the Audio/Video: cubeb componen
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16350
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16350
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16350
@@ -13608,7 +13608,7 @@ CVE-2026-16349 (Same-origin policy bypass in the DOM: Navigation component. This
{DSA-6394-1 DLA-4695-1}
- firefox 153.0-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16349
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16349
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16349
@@ -21091,7 +21091,7 @@ CVE-2026-15719 (We are aware that exploit code for this is public however we are
{DSA-6394-1 DLA-4695-1}
- firefox 152.0.6-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15719
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-15719
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-15719
@@ -21099,7 +21099,7 @@ CVE-2026-15718 (We are aware that exploit code for this is public however we are
{DSA-6394-1 DLA-4695-1}
- firefox 152.0.6-1
- firefox-esr 140.13.0esr-1
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15718
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-15718
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-15718
@@ -28474,11 +28474,11 @@ CVE-2026-58446 (Presenton before 0.8.8-beta bundles an MCP server that, on serve
CVE-2026-57995 (phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in ...)
NOT-FOR-US: phpMyFAQ
CVE-2026-57963 (An attacker who can send HTML chat messages (via Matrix or XMPP) can i ...)
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
[trixie] - thunderbird <postponed> (Minor issue, wait for next security round)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/#CVE-2026-57963
CVE-2026-57962 (A malicious LDAP server, which a Thunderbird user is configured to que ...)
- - thunderbird <unfixed>
+ - thunderbird 1:140.13.0esr-1
[trixie] - thunderbird <postponed> (Minor issue, wait for next security round)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/#CVE-2026-57962
CVE-2026-57585 (MessagePack is the serializer implementation for Python msgpack.org. P ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d63977a6ff4c6f8a62b18300e636891662055961
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d63977a6ff4c6f8a62b18300e636891662055961
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/b876adb3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list