[Git][security-tracker-team/security-tracker][master] Add thunderbird issues from mfsa2026-87

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 2 09:38:25 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8a8362ae by Salvatore Bonaccorso at 2026-09-02T10:38:01+02:00
Add thunderbird issues from mfsa2026-87

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -23,11 +23,14 @@ CVE-2026-84694 (Coolify before 4.2.0 fails to properly escape environment variab
 CVE-2026-84642 (The values of the mail.allowed_attachment_hostnames advanced config se ...)
 	TODO: check
 CVE-2026-84641 (A malicious IMAP server can trigger use-after-free and heap-memory dis ...)
-	TODO: check
+	- thunderbird <unfixed>
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84641
 CVE-2026-84640 (A maliciously constructed mail header could lead to a one byte read pa ...)
-	TODO: check
+	- thunderbird <unfixed>
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84640
 CVE-2026-84639 (Triggering an error condition in certain MIME bodies would cause unini ...)
-	TODO: check
+	- thunderbird <unfixed>
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84639
 CVE-2026-84637 (Malicious calendar invitations could use file URI attachments to launc ...)
 	TODO: check
 CVE-2026-84485 (APITable through 1.13.0-beta.1 exposes the internal organization loadO ...)
@@ -1144,16 +1147,20 @@ CVE-2023-54356 (Kyverno versions 1.9.4 and earlier support insecure 3DES cipher
 CVE-2026-84145 (Internally found bugs present in Thunderbird 154, Thunderbird ESR 153. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84145
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84145
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84145
 CVE-2026-84144 (Internally found bugs present in Thunderbird 154 and Thunderbird ESR 1 ...)
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84144
 CVE-2026-84143 (Internally found bugs present in Thunderbird 154, Thunderbird ESR 153. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84143
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84143
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84143
 CVE-2026-84142 (Internally found bugs present in Thunderbird 154. Some of these bugs s ...)
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84142
@@ -1190,8 +1197,10 @@ CVE-2026-84132 (Information disclosure in the Networking: HTTP component. This v
 CVE-2026-84131 (Privilege escalation due to invalid pointer in the Graphics component. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84131
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84131
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84131
 CVE-2026-84130 (Information disclosure in the Graphics: WebGPU component. This vulnera ...)
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84130
@@ -1213,31 +1222,41 @@ CVE-2026-84125 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
 CVE-2026-84124 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84124
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84124
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84124
 CVE-2026-84123 (Privilege escalation due to use-after-free in the Graphics: WebGPU com ...)
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84123
 CVE-2026-84122 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84122
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84122
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84122
 CVE-2026-84121 (Sandbox escape due to use-after-free in the DOM: Security component. T ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84121
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84121
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84121
 CVE-2026-84120 (Use-after-free in the Audio/Video component. This vulnerability was fi ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84120
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84120
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84120
 CVE-2026-84119 (Sandbox escape due to use-after-free in the DOM: Navigation component. ...)
 	- firefox 155.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84119
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-84119
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-84119
 CVE-2026-84118 (Use-after-free in the JavaScript: GC component. This vulnerability was ...)
 	- firefox 155.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-82/#CVE-2026-84118
@@ -15957,8 +15976,10 @@ CVE-2026-75890
 CVE-2026-75874 (Sandbox escape in the Remote Settings Client component. This vulnerabi ...)
 	- firefox 154.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-74/#CVE-2026-75874
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-75874
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-75874
 CVE-2026-75872 (HTML Injection in the public subscription form in maalfer MailerUp bef ...)
 	NOT-FOR-US: maalfer MailerUp
 CVE-2026-75859 (CodeWhale versions before 0.8.64 fail to validate file paths in the pr ...)
@@ -48931,6 +48952,7 @@ CVE-2026-16371 (Privilege escalation in the DOM: Navigation component. This vuln
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16371
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-72/#CVE-2026-16371
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-16371
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-16371
 CVE-2026-16370 (Mitigation bypass in the DOM: Networking component. This vulnerability ...)
 	- firefox 153.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16370
@@ -48999,8 +49021,10 @@ CVE-2026-16366 (Privilege escalation in the DOM: Navigation component. This vuln
 CVE-2026-16365 (Privilege escalation in the DOM: Workers component. This vulnerability ...)
 	- firefox 153.0-1
 	- firefox-esr 140.15.0esr-1
+	- thunderbird <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16365
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-84/#CVE-2026-16365
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-87/#CVE-2026-16365
 CVE-2026-16364 (Incorrect boundary conditions in the Audio/Video: Playback component.  ...)
 	- firefox 153.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16364



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a8362ae4d6c0bab2570ce5dc2b3e415200a27f9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a8362ae4d6c0bab2570ce5dc2b3e415200a27f9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/ed017f68/attachment.htm>


More information about the debian-security-tracker-commits mailing list