[Git][security-tracker-team/security-tracker][master] firefox and firefox-esr fixed in sid
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Aug 19 11:10:23 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fcceb072 by Moritz Muehlenhoff at 2026-08-19T12:09:58+02:00
firefox and firefox-esr fixed in sid
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2247,7 +2247,7 @@ CVE-2026-75897 (Improper input validation in the capabilities route handler in O
CVE-2026-75890
REJECTED
CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This vulnerabi ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-75874
CVE-2026-75872 (HTML Injection in the public subscription form in maalfer MailerUp bef ...)
NOT-FOR-US: maalfer MailerUp
@@ -2339,62 +2339,62 @@ CVE-2026-75032 (A flaw was found in BlueZ. Insufficient validation of packet len
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517490
TODO: check, Red Hat bugzilla entry (only source) contains no information
CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74990
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74990
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74990
CVE-2026-74989 (Internally found bugs present in Thunderbird 153. Some of these bugs s ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74989
CVE-2026-74988 (Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74988
CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, Thunderbird E ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74987
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74987
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74987
CVE-2026-74986 (Site isolation issue in the CSS Parsing and Computation component. Thi ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74986
CVE-2026-74985 (Privilege escalation in the Enterprise Policies component. This vulner ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74985
CVE-2026-74984 (Race condition in the JavaScript Engine component. This vulnerability ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74984
CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This vulnerab ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74983
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74983
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74983
CVE-2026-74982 (Denial-of-service in the Widget component. This vulnerability was fixe ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74982
CVE-2026-74981 (Site isolation issue in the Audio/Video: Web Codecs component. This vu ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74981
CVE-2026-74980 (Clickjacking issue in the Downloads component in Firefox for Android. ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74980
CVE-2026-74979 (Mitigation bypass in the Add-ons Manager component. This vulnerability ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74979
CVE-2026-74978 (Clickjacking issue in the Widget component. This vulnerability was fix ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74978
CVE-2026-74977 (Integer overflow in the Graphics component. This vulnerability was fix ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74977
CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74976
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74976
@@ -2403,232 +2403,232 @@ CVE-2026-74975 (Spoofing issue in the Downloads component in Firefox for Android
- firefox <not-affected> (Only affects Firefox on Android)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74975
CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. This vu ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74974
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This vulnera ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74973
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component. This ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74972
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling componen ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74971
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74971
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74971
CVE-2026-74970 (Site isolation issue in the Graphics component. This vulnerability was ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74970
CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This vulnerabi ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74969
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74969
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74969
CVE-2026-74968 (Site isolation issue in the Graphics: WebRender component. This vulner ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74968
CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback component. This ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74967
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74967
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74967
CVE-2026-74966 (Information disclosure in the Form Autofill component. This vulnerabil ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74966
CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vulnerab ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74965
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability was fix ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74964
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component. This v ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74963
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. This vulner ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74962
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74962
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74962
CVE-2026-74961 (Side-channel in the Web Audio component. This vulnerability was fixed ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74961
CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulnerabilit ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74960
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This vulnerabil ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74959
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74959
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74959
CVE-2026-74958 (Information disclosure in the WebRTC component. This vulnerability was ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74958
CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This vulnerability w ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74957
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74957
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74957
CVE-2026-74956 (Same-origin policy bypass in the DOM: Service Workers component. This ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74956
CVE-2026-74955 (Privilege escalation in the Request Handling component. This vulnerabi ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74955
CVE-2026-74954 (Information disclosure due to side-channel in the Storage: Cache API c ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74954
CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. This vulner ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74953
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74953
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74953
CVE-2026-74952 (Privilege escalation in the Application Update component. This vulnera ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74952
CVE-2026-74951 (Clickjacking issue in Firefox for Android. This vulnerability was fixe ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74951
CVE-2026-74950 (Privilege escalation in the Downloads API component. This vulnerabilit ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74950
CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canvas2D c ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74949
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
CVE-2026-74948 (Information disclosure in the Graphics component. This vulnerability w ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74948
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74948
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74948
CVE-2026-74947 (Privilege escalation due to invalid pointer in the Graphics component. ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74947
CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74946
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vulnerabi ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74945
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74944
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnerability ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74943
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. This vul ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74942
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. This vuln ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74941
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerability was ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74940
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74939
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74939
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74939
CVE-2026-74938 (Mitigation bypass in the JavaScript: GC component. This vulnerability ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74938
CVE-2026-74937 (Use-after-free in the JavaScript: GC component. This vulnerability was ...)
- - firefox <unfixed>
+ - firefox 154.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74937
CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74936
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vulnerabil ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74935
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. This vuln ...)
- - firefox <unfixed>
- - firefox-esr <unfixed>
+ - firefox 154.0-1
+ - firefox-esr 140.13.0esr-1
- thunderbird <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74934
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74934
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcceb07214dd6be463873b5d9289d73ead93ea7f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fcceb07214dd6be463873b5d9289d73ead93ea7f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/01b24678/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list