[Git][security-tracker-team/security-tracker][master] Track fixes for firefox via unstable upload
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 16 05:47:10 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e4fb4473 by Salvatore Bonaccorso at 2026-09-16T06:46:39+02:00
Track fixes for firefox via unstable upload
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -903,43 +903,43 @@ CVE-2026-92079 (Mitigation bypass in the Widget: Win32 component. This vulnerabi
- firefox <not-affected> (Only affects Firefox on Windows)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92079
CVE-2026-92078 (Denial-of-service in the Security component. This vulnerability was fi ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92078
CVE-2026-92077 (Denial-of-service in the SVG component. This vulnerability was fixed i ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92077
CVE-2026-92076 (Incorrect boundary conditions in the Networking component. This vulner ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92076
CVE-2026-92075 (Mitigation bypass in the Networking component. This vulnerability was ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92075
CVE-2026-92074 (Mitigation bypass in the Popup Blocker component. This vulnerability w ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92074
CVE-2026-92073 (Privilege escalation in the Enterprise Policies component. This vulner ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92073
CVE-2026-92072 (Incorrect boundary conditions in the Safe Browsing component. This vul ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92072
CVE-2026-92071 (Sandbox escape due to incorrect boundary conditions in the Widget: Win ...)
- firefox <not-affected> (Only affects Firefox on Windows)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92071
CVE-2026-92070 (Information disclosure in the Networking component. This vulnerability ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92070
CVE-2026-92069 (Spoofing issue in the DOM: Navigation component. This vulnerability wa ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92069
CVE-2026-92068 (Site isolation issue in the Reader Mode component. This vulnerability ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92068
CVE-2026-92067 (Use-after-free in the Widget: Gtk component. This vulnerability was fi ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92067
CVE-2026-92066 (Sandbox escape in the Profile Backup component. This vulnerability was ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92066
CVE-2026-92065 (Sandbox escape due to incorrect boundary conditions in the Widget: Win ...)
- firefox <not-affected> (Only affects Firefox on Windows)
@@ -948,56 +948,56 @@ CVE-2026-92064 (Sandbox escape due to incorrect boundary conditions in the Widge
- firefox <not-affected> (Only affects Firefox on Windows)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92064
CVE-2026-92063 (Denial-of-service in the Audio/Video component. This vulnerability was ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92063
CVE-2026-92062 (Privilege escalation in the Session Restore component. This vulnerabil ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92062
CVE-2026-92061 (Incorrect boundary conditions in the Security: Process Sandboxing comp ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92061
CVE-2026-92060 (Use-after-free in the Internationalization component. This vulnerabili ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92060
CVE-2026-92059 (Incorrect boundary conditions in the DOM: Editor component. This vulne ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92059
CVE-2026-92058 (Use-after-free in the Graphics component. This vulnerability was fixed ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92058
CVE-2026-92032 (Sandbox escape due to invalid pointer in the Graphics component. This ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92032
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92032
CVE-2026-92031 (Information disclosure in the Graphics: ImageLib component. This vulne ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92031
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92031
CVE-2026-92057 (Mitigation bypass in the Enterprise Policies component. This vulnerabi ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92057
CVE-2026-92056 (Use-after-free in the Graphics: Text component. This vulnerability was ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92056
CVE-2026-92055 (Privilege escalation in the DevTools component. This vulnerability was ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92055
CVE-2026-92054 (Privilege escalation in the Memory component. This vulnerability was f ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92054
CVE-2026-92053 (Privilege escalation in the Graphics: CanvasWebGL component. This vuln ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92053
CVE-2026-92052 (Privilege escalation due to uninitialized memory in the Graphics: Canv ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92052
CVE-2026-92051 (Spoofing issue due to invalid pointer in the Graphics component. This ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92051
CVE-2026-92050 (Sandbox escape due to race condition in the XPConnect component. This ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92050
CVE-2026-92049 (Use-after-free in the Widget: Win32 component. This vulnerability was ...)
- firefox <not-affected> (Only affects Firefox on Windows)
@@ -1006,164 +1006,164 @@ CVE-2026-92048 (Sandbox escape due to incorrect boundary conditions in the Widge
- firefox <not-affected> (Only affects Firefox on Windows)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92048
CVE-2026-92047 (Privilege escalation in the Crash Reporting component. This vulnerabil ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92047
CVE-2026-92046 (Use-after-free in the Graphics component. This vulnerability was fixed ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92046
CVE-2026-92030 (Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92030
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92030
CVE-2026-92045 (Sandbox escape due to incorrect boundary conditions in the WebRTC comp ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92045
CVE-2026-92044 (Information disclosure in the Networking: HTTP component. This vulnera ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92044
CVE-2026-92043 (Privilege escalation due to incorrect boundary conditions in the Audio ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92043
CVE-2026-92042 (Race condition in the DOM: Content Processes component. This vulnerabi ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92042
CVE-2026-92041 (Mitigation bypass in the DOM: Networking component. This vulnerability ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92041
CVE-2026-92040 (Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92040
CVE-2026-92039 (Mitigation bypass in the DOM: Notifications component. This vulnerabil ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92039
CVE-2026-92038 (Mitigation bypass in the Remote Settings Client component. This vulner ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92038
CVE-2026-92037 (Incorrect boundary conditions in the DOM: Animation component. This vu ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92037
CVE-2026-92029 (Use-after-free in the SVG component. This vulnerability was fixed in F ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92029
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92029
CVE-2026-92028 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92028
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92028
CVE-2026-92027 (Use-after-free in the DOM: Streams component. This vulnerability was f ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92027
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92027
CVE-2026-92036 (Incorrect boundary conditions in the Networking: HTTP component. This ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92036
CVE-2026-92026 (Use-after-free in the Networking component. This vulnerability was fix ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92026
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92026
CVE-2026-92025 (Use-after-free in the DOM: Navigation component. This vulnerability wa ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92025
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92025
CVE-2026-92024 (Use-after-free in the SVG component. This vulnerability was fixed in F ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92024
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92024
CVE-2026-92023 (Use-after-free in the XML component. This vulnerability was fixed in F ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92023
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92023
CVE-2026-92022 (Use-after-free in the DOM: HTML Parser component. This vulnerability w ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92022
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92022
CVE-2026-92020 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92020
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92020
CVE-2026-92019 (Mitigation bypass in the Remote Settings Client component. This vulner ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92019
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92019
CVE-2026-92018 (Sandbox escape in the DOM: Core & HTML component. This vulnerability w ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92018
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92018
CVE-2026-92017 (Privilege escalation in the DOM: Service Workers component. This vulne ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92017
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92017
CVE-2026-92016 (Use-after-free in the Disability Access APIs component. This vulnerabi ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92016
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92016
CVE-2026-92035 (Sandbox escape due to incorrect boundary conditions in the Graphics co ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92035
CVE-2026-92034 (Site isolation issue in the Graphics component. This vulnerability was ...)
- - firefox <unfixed>
+ - firefox 156.0-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92034
CVE-2026-92015 (Privilege escalation in the WebExtensions component. This vulnerabilit ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92015
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92015
CVE-2026-92013 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92013
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92013
CVE-2026-92012 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92012
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92012
CVE-2026-92011 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92011
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92011
CVE-2026-92010 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92010
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92010
CVE-2026-92009 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92009
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92009
CVE-2026-92008 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92008
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92008
CVE-2026-92007 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92007
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92007
CVE-2026-92006 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92006
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92006
CVE-2026-92005 (Use-after-free in the Audio/Video: Web Codecs component. This vulnerab ...)
- - firefox <unfixed>
+ - firefox 156.0-1
- firefox-esr <unfixed>
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92005
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92005
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4fb447308e3a0bb690508e32761ad3ac9bd9cb5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e4fb447308e3a0bb690508e32761ad3ac9bd9cb5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/0de5b7fc/attachment.htm>
More information about the debian-security-tracker-commits
mailing list