[Git][security-tracker-team/security-tracker][master] Track fixed version for thunderbird issues fixed via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 20 21:26:56 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0dc3b0ba by Salvatore Bonaccorso at 2026-08-20T21:35:59+02:00
Track fixed version for thunderbird issues fixed via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4329,7 +4329,7 @@ CVE-2026-74990 (Internally found bugs present in Thunderbird ESR 140.13, Thunder
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74990
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74990
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74990
@@ -4343,7 +4343,7 @@ CVE-2026-74987 (Internally found bugs present in Thunderbird ESR 140.13, Thunder
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74987
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74987
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74987
@@ -4360,7 +4360,7 @@ CVE-2026-74983 (Mitigation bypass in the Data Loss Prevention component. This vu
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74983
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74983
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74983
@@ -4386,7 +4386,7 @@ CVE-2026-74976 (JIT miscompilation in the JavaScript Engine: JIT component. This
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74976
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74976
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74976
@@ -4397,7 +4397,7 @@ CVE-2026-74974 (Same-origin policy bypass in the Graphics: ImageLib component. T
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74974
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74974
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74974
@@ -4405,7 +4405,7 @@ CVE-2026-74973 (Race condition, use-after-free in the Graphics component. This v
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74973
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74973
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74973
@@ -4413,7 +4413,7 @@ CVE-2026-74972 (Information disclosure in the DOM: Push Subscriptions component.
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74972
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74972
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74972
@@ -4421,7 +4421,7 @@ CVE-2026-74971 (Information disclosure in the DOM: UI Events & Focus Handling co
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74971
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74971
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74971
@@ -4432,7 +4432,7 @@ CVE-2026-74969 (Use-after-free in the Layout: Text and Fonts component. This vul
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74969
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74969
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74969
@@ -4443,7 +4443,7 @@ CVE-2026-74967 (Same-origin policy bypass in the Audio/Video: Playback component
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74967
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74967
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74967
@@ -4454,7 +4454,7 @@ CVE-2026-74965 (Privilege escalation in the Shell Integration component. This vu
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74965
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74965
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74965
@@ -4462,7 +4462,7 @@ CVE-2026-74964 (Integer overflow in the Graphics component. This vulnerability w
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74964
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74964
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74964
@@ -4470,7 +4470,7 @@ CVE-2026-74963 (Same-origin policy bypass in the Networking: Cookies component.
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74963
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74963
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74963
@@ -4478,7 +4478,7 @@ CVE-2026-74962 (Site isolation issue in the Networking: Cookies component. This
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74962
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74962
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74962
@@ -4489,7 +4489,7 @@ CVE-2026-74960 (Site isolation issue in the WebExtensions component. This vulner
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74960
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74960
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74960
@@ -4497,7 +4497,7 @@ CVE-2026-74959 (Mitigation bypass in the Storage: Cache API component. This vuln
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74959
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74959
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74959
@@ -4508,7 +4508,7 @@ CVE-2026-74957 (Mitigation bypass in the Safe Browsing component. This vulnerabi
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74957
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74957
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74957
@@ -4525,7 +4525,7 @@ CVE-2026-74953 (Privilege escalation in the Networking: Cookies component. This
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74953
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74953
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74953
@@ -4542,7 +4542,7 @@ CVE-2026-74949 (Privilege escalation due to use-after-free in the Graphics: Canv
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74949
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74949
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74949
@@ -4550,7 +4550,7 @@ CVE-2026-74948 (Information disclosure in the Graphics component. This vulnerabi
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74948
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74948
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74948
@@ -4561,7 +4561,7 @@ CVE-2026-74946 (Privilege escalation due to incorrect boundary conditions in the
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74946
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74946
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74946
@@ -4569,7 +4569,7 @@ CVE-2026-74945 (Information disclosure in the Graphics: Text component. This vul
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74945
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74945
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74945
@@ -4577,7 +4577,7 @@ CVE-2026-74944 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74944
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74944
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74944
@@ -4585,7 +4585,7 @@ CVE-2026-74943 (Use-after-free in the Graphics: ImageLib component. This vulnera
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74943
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74943
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74943
@@ -4593,7 +4593,7 @@ CVE-2026-74942 (Privilege escalation in the Remote Settings Client component. Th
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74942
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74942
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74942
@@ -4601,7 +4601,7 @@ CVE-2026-74941 (Privilege escalation in the Graphics: CanvasWebGL component. Thi
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74941
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74941
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74941
@@ -4609,7 +4609,7 @@ CVE-2026-74940 (Use-after-free in the Graphics: Text component. This vulnerabili
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74940
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74940
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74940
@@ -4617,7 +4617,7 @@ CVE-2026-74939 (Privilege escalation in the DOM: Navigation component. This vuln
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74939
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74939
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74939
@@ -4631,7 +4631,7 @@ CVE-2026-74936 (Use-after-free in the JavaScript: WebAssembly component. This vu
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74936
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74936
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74936
@@ -4639,7 +4639,7 @@ CVE-2026-74935 (Privilege escalation in the DOM: Networking component. This vuln
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74935
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74935
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74935
@@ -4647,7 +4647,7 @@ CVE-2026-74934 (Site isolation issue in the Graphics: CanvasWebGL component. Thi
 	{DSA-6451-1}
 	- firefox 154.0-1
 	- firefox-esr 140.14.0esr-2
-	- thunderbird <unfixed>
+	- thunderbird 1:140.14.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-74934
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-76/#CVE-2026-74934
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/#CVE-2026-74934



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0dc3b0ba6ba33e23cc59f1365a774ccf82664cb3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0dc3b0ba6ba33e23cc59f1365a774ccf82664cb3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/5ee74daf/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list