[Git][security-tracker-team/security-tracker][master] Add additional references from mfsa2026-96

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 17 19:16:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
adfbaaa8 by Salvatore Bonaccorso at 2026-09-17T20:15:44+02:00
Add additional references from mfsa2026-96

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2840,12 +2840,15 @@ CVE-2024-11222 (GitLab has remediated an issue in GitLab CE/EE affecting all ver
 CVE-2026-92238 (A maliciously constructed mail header could lead to multiple fields be ...)
 	{DSA-6503-1}
 	- thunderbird 1:153.3.0esr-1
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92238
 CVE-2026-92239 (A maliciously constructed IMAP line could cause an out-of-bounds buffe ...)
 	{DSA-6503-1}
 	- thunderbird 1:153.3.0esr-1
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92239
 CVE-2026-92240 (A malicious or compromised IMAP server can trigger an out-of-bounds re ...)
 	{DSA-6503-1}
 	- thunderbird 1:153.3.0esr-1
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92240
 CVE-2026-91841 [Incomplete fix of CVE-2018-10900]
 	- network-manager-vpnc <unfixed> (bug #1148113)
 	NOTE: https://gitlab.gnome.org/Archive/NetworkManager-vpnc/-/work_items/20
@@ -4975,70 +4978,108 @@ CVE-2023-54397 (Tornado before 6.3.3 contains an HTTP request smuggling vulnerab
 	NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-qppv-j76h-2rpx
 CVE-2026-92079 (Mitigation bypass in the Widget: Win32 component. This vulnerability w ...)
 	- firefox <not-affected> (Only affects Firefox on Windows)
+	- thunderbird <not-affected> (Only affects Thunderbird on Windows)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92079
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92079
 CVE-2026-92078 (Denial-of-service in the Security component. This vulnerability was fi ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92078
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92078
 CVE-2026-92077 (Denial-of-service in the SVG component. This vulnerability was fixed i ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92077
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92077
 CVE-2026-92076 (Incorrect boundary conditions in the Networking component. This vulner ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92076
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92076
 CVE-2026-92075 (Mitigation bypass in the Networking component. This vulnerability was  ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92075
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92075
 CVE-2026-92074 (Mitigation bypass in the Popup Blocker component. This vulnerability w ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92074
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92074
 CVE-2026-92073 (Privilege escalation in the Enterprise Policies component. This vulner ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92073
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92073
 CVE-2026-92072 (Incorrect boundary conditions in the Safe Browsing component. This vul ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92072
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92072
 CVE-2026-92071 (Sandbox escape due to incorrect boundary conditions in the Widget: Win ...)
 	- firefox <not-affected> (Only affects Firefox on Windows)
+	- thunderbird <not-affected> (Only affects Thunderbird on Windows)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92071
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92071
 CVE-2026-92070 (Information disclosure in the Networking component. This vulnerability ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92070
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92070
 CVE-2026-92069 (Spoofing issue in the DOM: Navigation component. This vulnerability wa ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92069
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92069
 CVE-2026-92068 (Site isolation issue in the Reader Mode component. This vulnerability  ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92068
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92068
 CVE-2026-92067 (Use-after-free in the Widget: Gtk component. This vulnerability was fi ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92067
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92067
 CVE-2026-92066 (Sandbox escape in the Profile Backup component. This vulnerability was ...)
 	- firefox 156.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92066
 CVE-2026-92065 (Sandbox escape due to incorrect boundary conditions in the Widget: Win ...)
 	- firefox <not-affected> (Only affects Firefox on Windows)
+	- thunderbird <not-affected> (Only affects Thunderbird on Windows)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92065
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92065
 CVE-2026-92064 (Sandbox escape due to incorrect boundary conditions in the Widget: Win ...)
 	- firefox <not-affected> (Only affects Firefox on Windows)
+	- thunderbird <not-affected> (Only affects Thunderbird on Windows)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92064
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92064
 CVE-2026-92063 (Denial-of-service in the Audio/Video component. This vulnerability was ...)
 	- firefox 156.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92063
 CVE-2026-92062 (Privilege escalation in the Session Restore component. This vulnerabil ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92062
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92062
 CVE-2026-92061 (Incorrect boundary conditions in the Security: Process Sandboxing comp ...)
 	- firefox 156.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92061
 CVE-2026-92060 (Use-after-free in the Internationalization component. This vulnerabili ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92060
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92060
 CVE-2026-92059 (Incorrect boundary conditions in the DOM: Editor component. This vulne ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92059
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92059
 CVE-2026-92058 (Use-after-free in the Graphics component. This vulnerability was fixed ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92058
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92058
 CVE-2026-92032 (Sandbox escape due to invalid pointer in the Graphics component. This  ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5046,6 +5087,7 @@ CVE-2026-92032 (Sandbox escape due to invalid pointer in the Graphics component.
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92032
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92032
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92032
 CVE-2026-92031 (Information disclosure in the Graphics: ImageLib component. This vulne ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5053,24 +5095,37 @@ CVE-2026-92031 (Information disclosure in the Graphics: ImageLib component. This
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92031
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92031
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92031
 CVE-2026-92057 (Mitigation bypass in the Enterprise Policies component. This vulnerabi ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92057
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92057
 CVE-2026-92056 (Use-after-free in the Graphics: Text component. This vulnerability was ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92056
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92056
 CVE-2026-92055 (Privilege escalation in the DevTools component. This vulnerability was ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92055
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92055
 CVE-2026-92054 (Privilege escalation in the Memory component. This vulnerability was f ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92054
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92054
 CVE-2026-92053 (Privilege escalation in the Graphics: CanvasWebGL component. This vuln ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92053
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92053
 CVE-2026-92052 (Privilege escalation due to uninitialized memory in the Graphics: Canv ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92052
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92052
 CVE-2026-92051 (Spoofing issue due to invalid pointer in the Graphics component. This  ...)
 	- firefox 156.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92051
@@ -5079,16 +5134,24 @@ CVE-2026-92050 (Sandbox escape due to race condition in the XPConnect component.
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92050
 CVE-2026-92049 (Use-after-free in the Widget: Win32 component. This vulnerability was  ...)
 	- firefox <not-affected> (Only affects Firefox on Windows)
+	- thunderbird <not-affected> (Only affects Thunderbird on Windows)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92049
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92049
 CVE-2026-92048 (Sandbox escape due to incorrect boundary conditions in the Widget: Win ...)
 	- firefox <not-affected> (Only affects Firefox on Windows)
+	- thunderbird <not-affected> (Only affects Thunderbird on Windows)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92048
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92048
 CVE-2026-92047 (Privilege escalation in the Crash Reporting component. This vulnerabil ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92047
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92047
 CVE-2026-92046 (Use-after-free in the Graphics component. This vulnerability was fixed ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92046
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92046
 CVE-2026-92030 (Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component.  ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5096,30 +5159,45 @@ CVE-2026-92030 (Mitigation bypass in the DOM: Copy & Paste and Drag & Drop compo
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92030
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92030
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92030
 CVE-2026-92045 (Sandbox escape due to incorrect boundary conditions in the WebRTC comp ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92045
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92045
 CVE-2026-92044 (Information disclosure in the Networking: HTTP component. This vulnera ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92044
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92044
 CVE-2026-92043 (Privilege escalation due to incorrect boundary conditions in the Audio ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92043
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92043
 CVE-2026-92042 (Race condition in the DOM: Content Processes component. This vulnerabi ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92042
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92042
 CVE-2026-92041 (Mitigation bypass in the DOM: Networking component. This vulnerability ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92041
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92041
 CVE-2026-92040 (Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
 	- firefox 156.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92040
 CVE-2026-92039 (Mitigation bypass in the DOM: Notifications component. This vulnerabil ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92039
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92039
 CVE-2026-92038 (Mitigation bypass in the Remote Settings Client component. This vulner ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92038
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92038
 CVE-2026-92037 (Incorrect boundary conditions in the DOM: Animation component. This vu ...)
 	- firefox 156.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92037
@@ -5130,6 +5208,7 @@ CVE-2026-92029 (Use-after-free in the SVG component. This vulnerability was fixe
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92029
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92029
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92029
 CVE-2026-92028 (Use-after-free in the DOM: Core & HTML component. This vulnerability w ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5137,6 +5216,7 @@ CVE-2026-92028 (Use-after-free in the DOM: Core & HTML component. This vulnerabi
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92028
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92028
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92028
 CVE-2026-92027 (Use-after-free in the DOM: Streams component. This vulnerability was f ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5144,6 +5224,7 @@ CVE-2026-92027 (Use-after-free in the DOM: Streams component. This vulnerability
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92027
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92027
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92027
 CVE-2026-92036 (Incorrect boundary conditions in the Networking: HTTP component. This  ...)
 	- firefox 156.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92036
@@ -5154,6 +5235,7 @@ CVE-2026-92026 (Use-after-free in the Networking component. This vulnerability w
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92026
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92026
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92026
 CVE-2026-92025 (Use-after-free in the DOM: Navigation component. This vulnerability wa ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5161,6 +5243,7 @@ CVE-2026-92025 (Use-after-free in the DOM: Navigation component. This vulnerabil
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92025
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92025
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92025
 CVE-2026-92024 (Use-after-free in the SVG component. This vulnerability was fixed in F ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5168,6 +5251,7 @@ CVE-2026-92024 (Use-after-free in the SVG component. This vulnerability was fixe
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92024
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92024
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92024
 CVE-2026-92023 (Use-after-free in the XML component. This vulnerability was fixed in F ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5175,6 +5259,7 @@ CVE-2026-92023 (Use-after-free in the XML component. This vulnerability was fixe
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92023
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92023
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92023
 CVE-2026-92022 (Use-after-free in the DOM: HTML Parser component. This vulnerability w ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5182,6 +5267,7 @@ CVE-2026-92022 (Use-after-free in the DOM: HTML Parser component. This vulnerabi
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92022
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92022
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92022
 CVE-2026-92020 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5189,6 +5275,7 @@ CVE-2026-92020 (Privilege escalation due to incorrect boundary conditions in the
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92020
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92020
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92020
 CVE-2026-92019 (Mitigation bypass in the Remote Settings Client component. This vulner ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5196,6 +5283,7 @@ CVE-2026-92019 (Mitigation bypass in the Remote Settings Client component. This
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92019
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92019
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92019
 CVE-2026-92018 (Sandbox escape in the DOM: Core & HTML component. This vulnerability w ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5203,6 +5291,7 @@ CVE-2026-92018 (Sandbox escape in the DOM: Core & HTML component. This vulnerabi
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92018
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92018
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92018
 CVE-2026-92017 (Privilege escalation in the DOM: Service Workers component. This vulne ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5210,6 +5299,7 @@ CVE-2026-92017 (Privilege escalation in the DOM: Service Workers component. This
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92017
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92017
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92017
 CVE-2026-92016 (Use-after-free in the Disability Access APIs component. This vulnerabi ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5217,9 +5307,12 @@ CVE-2026-92016 (Use-after-free in the Disability Access APIs component. This vul
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92016
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92016
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92016
 CVE-2026-92035 (Sandbox escape due to incorrect boundary conditions in the Graphics co ...)
 	- firefox 156.0-1
+	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92035
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92035
 CVE-2026-92034 (Site isolation issue in the Graphics component. This vulnerability was ...)
 	- firefox 156.0-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92034
@@ -5230,6 +5323,7 @@ CVE-2026-92015 (Privilege escalation in the WebExtensions component. This vulner
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92015
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92015
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92015
 CVE-2026-92013 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5237,6 +5331,7 @@ CVE-2026-92013 (Privilege escalation due to incorrect boundary conditions in the
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92013
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92013
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92013
 CVE-2026-92012 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5244,6 +5339,7 @@ CVE-2026-92012 (Privilege escalation due to incorrect boundary conditions in the
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92012
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92012
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92012
 CVE-2026-92011 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5251,6 +5347,7 @@ CVE-2026-92011 (Privilege escalation due to incorrect boundary conditions in the
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92011
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92011
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92011
 CVE-2026-92010 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5258,6 +5355,7 @@ CVE-2026-92010 (Privilege escalation due to incorrect boundary conditions in the
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92010
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92010
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92010
 CVE-2026-92009 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5265,6 +5363,7 @@ CVE-2026-92009 (Privilege escalation due to incorrect boundary conditions in the
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92009
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92009
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92009
 CVE-2026-92008 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5272,6 +5371,7 @@ CVE-2026-92008 (Privilege escalation due to incorrect boundary conditions in the
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92008
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92008
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92008
 CVE-2026-92007 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5279,6 +5379,7 @@ CVE-2026-92007 (Privilege escalation due to incorrect boundary conditions in the
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92007
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92007
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92007
 CVE-2026-92006 (Privilege escalation due to incorrect boundary conditions in the Graph ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5286,6 +5387,7 @@ CVE-2026-92006 (Privilege escalation due to incorrect boundary conditions in the
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92006
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92006
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92006
 CVE-2026-92005 (Use-after-free in the Audio/Video: Web Codecs component. This vulnerab ...)
 	{DSA-6503-1 DSA-6501-1}
 	- firefox 156.0-1
@@ -5293,6 +5395,7 @@ CVE-2026-92005 (Use-after-free in the Audio/Video: Web Codecs component. This vu
 	- thunderbird 1:153.3.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92005
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-92/#CVE-2026-92005
+	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92005
 CVE-2026-92033 (Privilege escalation in Firefox for Android. This vulnerability was fi ...)
 	- firefox <not-affected> (Only affects Firefox on Android)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92033



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/adfbaaa8a0bec2f8fc834f1a784e477a4d89dc97

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/adfbaaa8a0bec2f8fc834f1a784e477a4d89dc97
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/19e21d0a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list