[Git][security-tracker-team/security-tracker][master] Add CVEs for thunderbird from mfsa2026-72

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 10:26:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d1250199 by Salvatore Bonaccorso at 2026-07-26T11:25:31+02:00
Add CVEs for thunderbird from mfsa2026-72

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2850,7 +2850,8 @@ CVE-2026-16628 (A vulnerability was detected in oclif up to 4.23.16. Affected by
 CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to reject dot ...)
 	NOT-FOR-US: fastify/static
 CVE-2026-14899 (The code to parse MIME headers for display when forwarding a message ( ...)
-	TODO: check
+	- thunderbird <unfixed>
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-14899
 CVE-2026-14881 (When importing connections in Compass it is possible to override some  ...)
 	NOT-FOR-US: mongodb-js (not same as node-mongodb)
 CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does not veri ...)
@@ -6208,19 +6209,25 @@ CVE-2026-15226 (A sandbox confinement bypass vulnerability exists in Canonical s
 CVE-2026-16361 (Memory safety bugs present in Thunderbird ESR 140.12. Some of these bu ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16361
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16361
 CVE-2026-16360 (Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 a ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16360
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16360
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16360
 CVE-2026-16412 (Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16412
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16412
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16412
 CVE-2026-16411 (Memory safety bugs present in Firefox 152. Some of these bugs showed e ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16411
@@ -6243,8 +6250,10 @@ CVE-2026-16405 (Information disclosure in the Networking: WebSockets component.
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16405
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16405
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16405
 CVE-2026-16404 (Spoofing issue in Firefox for Android. This vulnerability was fixed in ...)
 	- firefox <not-affected> (Only affects Firefox on Android)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16404
@@ -6273,8 +6282,10 @@ CVE-2026-16396 (Privilege escalation in WebExtensions. This vulnerability was fi
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16396
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16396
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16396
 CVE-2026-16395 (Integer overflow in the Audio/Video component. This vulnerability was  ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16395
@@ -6285,8 +6296,10 @@ CVE-2026-16359 (Incorrect boundary conditions in the Audio/Video: GMP component.
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16359
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16359
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16359
 CVE-2026-16393 (Incorrect boundary conditions in the Graphics: WebGPU component. This  ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16393
@@ -6297,14 +6310,18 @@ CVE-2026-16391 (Information disclosure in the Storage: IndexedDB component. This
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16391
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16391
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16391
 CVE-2026-16390 (Mitigation bypass in the Enterprise Policies component. This vulnerabi ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16390
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16390
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16390
 CVE-2026-16389 (Incorrect boundary conditions, integer overflow in the Libraries compo ...)
 	- firefox <unfixed>
 	- nss 2:3.126-1
@@ -6317,8 +6334,10 @@ CVE-2026-16387 (Site isolation issue in the Networking component. This vulnerabi
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16387
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16387
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16387
 CVE-2026-16386 (Information disclosure due to uninitialized memory in the Graphics: We ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16386
@@ -6332,8 +6351,10 @@ CVE-2026-16383 (Mitigation bypass in the DOM: Networking component. This vulnera
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16383
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16383
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16383
 CVE-2026-16382 (Mitigation bypass in the DOM: Service Workers component. This vulnerab ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16382
@@ -6341,8 +6362,10 @@ CVE-2026-16381 (Same-origin policy bypass in the Networking: DNS component. This
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16381
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16381
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16381
 CVE-2026-16380 (Mitigation bypass in the Networking component. This vulnerability was  ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16380
@@ -6350,14 +6373,18 @@ CVE-2026-16358 (Site isolation issue in the Graphics: WebRender component. This
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16358
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16358
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16358
 CVE-2026-16379 (Privilege escalation in the DOM: Content Processes component. This vul ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16379
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16379
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16379
 CVE-2026-16378 (Other issue in the DOM: Copy & Paste and Drag & Drop component. This v ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16378
@@ -6365,8 +6392,10 @@ CVE-2026-16377 (Mitigation bypass in the PDF Viewer component. This vulnerabilit
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16377
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16377
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16377
 CVE-2026-16376 (Denial-of-service in the Graphics: WebGPU component. This vulnerabilit ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16376
@@ -6374,14 +6403,18 @@ CVE-2026-16375 (Site isolation issue in the Networking: HTTP component. This vul
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16375
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16375
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16375
 CVE-2026-16374 (Information disclosure in the Framework component in DevTools. This vu ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16374
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16374
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16374
 CVE-2026-16373 (Information disclosure in the Privacy component in Firefox for Android ...)
 	- firefox <not-affected> (Only affects Firefox on Android)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16373
@@ -6392,8 +6425,10 @@ CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This vuln
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16371
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16371
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16371
 CVE-2026-16370 (Mitigation bypass in the DOM: Networking component. This vulnerability ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16370
@@ -6401,47 +6436,61 @@ CVE-2026-16357 (Incorrect boundary conditions in the Graphics component. This vu
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16357
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16357
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16357
 CVE-2026-16356 (Sandbox escape due to use-after-free in the Disability Access APIs com ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16356
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16356
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16356
 CVE-2026-16355 (JIT miscompilation in the JavaScript Engine: JIT component. This vulne ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16355
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16355
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16355
 CVE-2026-16369 (Integer overflow in the JavaScript: WebAssembly component. This vulner ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16369
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16369
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16369
 CVE-2026-16368 (Incorrect boundary conditions in the JavaScript: WebAssembly component ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16368
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16368
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16368
 CVE-2026-16367 (Sandbox escape due to invalid pointer in the Disability Access APIs co ...)
 	- firefox <unfixed>
-	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16367
 CVE-2026-16354 (Information disclosure in the Graphics: ImageLib component. This vulne ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16354
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16354
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16354
 CVE-2026-16353 (Invalid pointer in the DOM: Bindings (WebIDL) component. This vulnerab ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16353
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16353
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16353
 CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This vulnerabil ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16366
@@ -6455,38 +6504,50 @@ CVE-2026-16363 (JIT miscompilation in the JavaScript: WebAssembly component. Thi
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16363
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16363
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16363
 CVE-2026-16352 (Sandbox escape due to use-after-free in the Disability Access APIs com ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16352
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16352
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16352
 CVE-2026-16351 (Sandbox escape due to use-after-free in the DOM: Navigation component. ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16351
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16351
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16351
 CVE-2026-16362 (Use-after-free in the WebRTC: Audio/Video component. This vulnerabilit ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16362
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16362
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16362
 CVE-2026-16350 (Incorrect boundary conditions in the Audio/Video: cubeb component. Thi ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16350
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16350
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16350
 CVE-2026-16349 (Same-origin policy bypass in the DOM: Navigation component. This vulne ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox <unfixed>
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16349
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16349
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16349
 CVE-2026-15370 (A flaw was found in libssh. During SFTP server directory listing, the  ...)
 	- libssh <unfixed> (bug #1142537)
 	NOTE: https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/
@@ -13832,14 +13893,18 @@ CVE-2026-15719 (We are aware that exploit code for this is public however we are
 	{DSA-6394-1 DLA-4695-1}
 	- firefox 152.0.6-1
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15719
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-15719
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-15719
 CVE-2026-15718 (We are aware that exploit code for this is public however we are not a ...)
 	{DSA-6394-1 DLA-4695-1}
 	- firefox 152.0.6-1
 	- firefox-esr 140.13.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/#CVE-2026-15718
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-15718
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-15718
 CVE-2026-42491
 	- xen-api <removed>
 	NOTE: https://xenbits.xen.org/xsa/advisory-498.html



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1250199f12197234ea09f410ae6e63dd42dfe67

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1250199f12197234ea09f410ae6e63dd42dfe67
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/2e612561/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list