[Git][security-tracker-team/security-tracker][master] Add firefox-esr issues from mfsa2026-92
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 16 05:44:29 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
729c17dd by Salvatore Bonaccorso at 2026-09-16T06:42:26+02:00
Add firefox-esr issues from mfsa2026-92
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11,9 +11,11 @@ CVE-2026-92176 (pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code
CVE-2026-92082 (By default, Payara Server does not limit the number of failed login at ...)
NOT-FOR-US: Payara
CVE-2026-92021 (Use-after-free in the JavaScript Engine: JIT component. This vulnerabi ...)
- TODO: check
+ - firefox-esr <unfixed>
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92021
CVE-2026-92014 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- TODO: check
+ - firefox-esr <unfixed>
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92014
CVE-2026-92003 (Affected versions of MISP do not consistently apply the existing authe ...)
- misp <itp> (bug #1144317)
CVE-2026-92002 (Affected versions of MISP use Redis to throttle repeated authenticatio ...)
@@ -965,10 +967,14 @@ CVE-2026-92058 (Use-after-free in the Graphics component. This vulnerability was
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92058
CVE-2026-92032 (Sandbox escape due to invalid pointer in the Graphics component. This ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92032
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92032
CVE-2026-92031 (Information disclosure in the Graphics: ImageLib component. This vulne ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92031
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92031
CVE-2026-92057 (Mitigation bypass in the Enterprise Policies component. This vulnerabi ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92057
@@ -1007,7 +1013,9 @@ CVE-2026-92046 (Use-after-free in the Graphics component. This vulnerability was
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92046
CVE-2026-92030 (Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92030
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92030
CVE-2026-92045 (Sandbox escape due to incorrect boundary conditions in the WebRTC comp ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92045
@@ -1037,46 +1045,72 @@ CVE-2026-92037 (Incorrect boundary conditions in the DOM: Animation component. T
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92037
CVE-2026-92029 (Use-after-free in the SVG component. This vulnerability was fixed in F ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92029
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92029
CVE-2026-92028 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92028
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92028
CVE-2026-92027 (Use-after-free in the DOM: Streams component. This vulnerability was f ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92027
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92027
CVE-2026-92036 (Incorrect boundary conditions in the Networking: HTTP component. This ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92036
CVE-2026-92026 (Use-after-free in the Networking component. This vulnerability was fix ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92026
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92026
CVE-2026-92025 (Use-after-free in the DOM: Navigation component. This vulnerability wa ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92025
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92025
CVE-2026-92024 (Use-after-free in the SVG component. This vulnerability was fixed in F ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92024
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92024
CVE-2026-92023 (Use-after-free in the XML component. This vulnerability was fixed in F ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92023
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92023
CVE-2026-92022 (Use-after-free in the DOM: HTML Parser component. This vulnerability w ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92022
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92022
CVE-2026-92020 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92020
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92020
CVE-2026-92019 (Mitigation bypass in the Remote Settings Client component. This vulner ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92019
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92019
CVE-2026-92018 (Sandbox escape in the DOM: Core & HTML component. This vulnerability w ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92018
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92018
CVE-2026-92017 (Privilege escalation in the DOM: Service Workers component. This vulne ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92017
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92017
CVE-2026-92016 (Use-after-free in the Disability Access APIs component. This vulnerabi ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92016
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92016
CVE-2026-92035 (Sandbox escape due to incorrect boundary conditions in the Graphics co ...)
- firefox <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92035
@@ -1085,34 +1119,54 @@ CVE-2026-92034 (Site isolation issue in the Graphics component. This vulnerabili
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92034
CVE-2026-92015 (Privilege escalation in the WebExtensions component. This vulnerabilit ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92015
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92015
CVE-2026-92013 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92013
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92013
CVE-2026-92012 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92012
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92012
CVE-2026-92011 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92011
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92011
CVE-2026-92010 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92010
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92010
CVE-2026-92009 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92009
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92009
CVE-2026-92008 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92008
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92008
CVE-2026-92007 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92007
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92007
CVE-2026-92006 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92006
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92006
CVE-2026-92005 (Use-after-free in the Audio/Video: Web Codecs component. This vulnerab ...)
- firefox <unfixed>
+ - firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92005
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92005
CVE-2026-92033 (Privilege escalation in Firefox for Android. This vulnerability was fi ...)
- firefox <not-affected> (Only affects Firefox on Android)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92033
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/729c17dd6dfb7932b5317782dea3087907541cbc
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/729c17dd6dfb7932b5317782dea3087907541cbc
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/9fdc7494/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list