Security update for MozillaThunderbird
This update for MozillaThunderbird fixes the following issues: Changes in MozillaThunderbird: - Mozilla Thunderbird 140.10.0 ESR * Newly translated strings were not available in Thunderbird MFSA 2026-34 (bsc#1262230) * CVE-2026-6746 Use-after-free in the DOM: Core & HTML component * CVE-2026-6747 Use-after-free in the WebRTC component * CVE-2026-6748 Uninitialized memory in the Audio/Video: Web Codecs component * CVE-2026-6749 Information disclosure due to uninitialized memory in the Graphics: Canvas2D component * CVE-2026-6750 Privilege escalation in the Graphics: WebRender component * CVE-2026-6751 Uninitialized memory in the Audio/Video: Web Codecs component * CVE-2026-6752 Incorrect boundary conditions in the WebRTC component * CVE-2026-6753 Incorrect boundary conditions in the WebRTC component * CVE-2026-6754 Use-after-free in the JavaScript Engine component * CVE-2026-6757 Invalid pointer in the JavaScript: WebAssembly component * CVE-2026-6759 Use-after-free in the Widget: Cocoa component * CVE-2026-6761 Privilege escalation in the Networking component * CVE-2026-6762 Spoofing issue in the DOM: Core & HTML component * CVE-2026-6763 Mitigation bypass in the File Handling component * CVE-2026-6764 Incorrect boundary conditions in the DOM: Device Interfaces component * CVE-2026-6765 Information disclosure in the Form Autofill component * CVE-2026-6766 Incorrect boundary conditions in the Libraries component in NSS * CVE-2026-6767 Other issue in the Libraries component in NSS * CVE-2026-6769 Privilege escalation in the Debugger component * CVE-2026-6770 Other issue in the Storage: IndexedDB component * CVE-2026-6771 Mitigation bypass in the DOM: Security component * CVE-2026-6772 Incorrect boundary conditions in the Libraries component in NSS * CVE-2026-6776 Incorrect boundary conditions in the WebRTC: Networking component * CVE-2026-6785 Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 * CVE-2026-6786 Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 - Mozilla Thunderbird 140.9.1 ESR MFSA 2026-29 * CVE-2026-5732 Incorrect boundary conditions, integer overflow in the Graphics: Text component * CVE-2026-5731 Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 * CVE-2026-5734 Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 - Mozilla Thunderbird 140.9.0 ESR MFSA 2026-24 (bsc#1260083) * CVE-2026-3889 Spoofing issue in Thunderbird * CVE-2026-4371 Out of bounds read in IMAP parsing * CVE-2026-4684 Race condition, use-after-free in the Graphics: WebRender component * CVE-2026-4685 Incorrect boundary conditions in the Graphics: Canvas2D component * CVE-2026-4686 Incorrect boundary conditions in the Graphics: Canvas2D component * CVE-2026-4687 Sandbox escape due to incorrect boundary conditions in the Telemetry component * CVE-2026-4688 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-4689 Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component * CVE-2026-4690 Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component * CVE-2026-4691 Use-after-free in the CSS Parsing and Computation component * CVE-2026-4692 Sandbox escape in the Responsive Design Mode component * CVE-2026-4693 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-4694 Incorrect boundary conditions, integer overflow in the Graphics component * CVE-2026-4695 Incorrect boundary conditions in the Audio/Video: Web Codecs component * CVE-2026-4696 Use-after-free in the Layout: Text and Fonts component * CVE-2026-4697 Incorrect boundary conditions in the Audio/Video: Web Codecs component * CVE-2026-4698 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-4699 Incorrect boundary conditions in the Layout: Text and Fonts component * CVE-2026-4700 Mitigation bypass in the Networking: HTTP component * CVE-2026-4701 Use-after-free in the JavaScript Engine component * CVE-2026-4702 JIT miscompilation in the JavaScript Engine component * CVE-2026-4704 Denial-of-service in the WebRTC: Signaling component * CVE-2026-4705 Undefined behavior in the WebRTC: Signaling component * CVE-2026-4706 Incorrect boundary conditions in the Graphics: Canvas2D component * CVE-2026-4707 Incorrect boundary conditions in the Graphics: Canvas2D component * CVE-2026-4708 Incorrect boundary conditions in the Graphics component * CVE-2026-4709 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-4710 Incorrect boundary conditions in the Audio/Video component * CVE-2026-4711 Use-after-free in the Widget: Cocoa component * CVE-2026-4712 Information disclosure in the Widget: Cocoa component * CVE-2026-4713 Incorrect boundary conditions in the Graphics component * CVE-2026-4714 Incorrect boundary conditions in the Audio/Video component * CVE-2026-4715 Uninitialized memory in the Graphics: Canvas2D component * CVE-2026-4716 Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component * CVE-2026-4717 Privilege escalation in the Netmonitor component * CVE-2025-59375 Denial-of-service in the XML component * CVE-2026-4718 Undefined behavior in the WebRTC: Signaling component * CVE-2026-4719 Incorrect boundary conditions in the Graphics: Text component * CVE-2026-4720 Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 * CVE-2026-4721 Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for MozillaThunderbird fixes the following issues: Changes in MozillaThunderbird: - Mozilla Thunderbird 140.10.0 ESR * Newly translated strings were not available in Thunderbird MFSA 2026-34 (bsc#1262230) * CVE-2026-6746 Use-after-free in the DOM: Core & HTML component * CVE-2026-6747 Use-after-free in the WebRTC component * CVE-2026-6748 Uninitialized memory in the Audio/Video: Web Codecs component * CVE-2026-6749 Information disclosure due to uninitialized memory in the Graphics: Canvas2D component * CVE-2026-6750 Privilege escalation in the Graphics: WebRender component * CVE-2026-6751 Uninitialized memory in the Audio/Video: Web Codecs component * CVE-2026-6752 Incorrect boundary conditions in the WebRTC component * CVE-2026-6753 Incorrect boundary conditions in the WebRTC component * CVE-2026-6754 Use-after-free in the JavaScript Engine component * CVE-2026-6757 Invalid pointer in the JavaScript: WebAssembly component * CVE-2026-6759 Use-after-free in the Widget: Cocoa component * CVE-2026-6761 Privilege escalation in the Networking component * CVE-2026-6762 Spoofing issue in the DOM: Core & HTML component * CVE-2026-6763 Mitigation bypass in the File Handling component * CVE-2026-6764 Incorrect boundary conditions in the DOM: Device Interfaces component * CVE-2026-6765 Information disclosure in the Form Autofill component * CVE-2026-6766 Incorrect boundary conditions in the Libraries component in NSS * CVE-2026-6767 Other issue in the Libraries component in NSS * CVE-2026-6769 Privilege escalation in the Debugger component * CVE-2026-6770 Other issue in the Storage: IndexedDB component * CVE-2026-6771 Mitigation bypass in the DOM: Security component * CVE-2026-6772 Incorrect boundary conditions in the Libraries component in NSS * CVE-2026-6776 Incorrect boundary conditions in the WebRTC: Networking component * CVE-2026-6785 Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 * CVE-2026-6786 Memory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150 - Mozilla Thunderbird 140.9.1 ESR MFSA 2026-29 * CVE-2026-5732 Incorrect boundary conditions, integer overflow in the Graphics: Text component * CVE-2026-5731 Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 * CVE-2026-5734 Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 - Mozilla Thunderbird 140.9.0 ESR MFSA 2026-24 (bsc#1260083) * CVE-2026-3889 Spoofing issue in Thunderbird * CVE-2026-4371 Out of bounds read in IMAP parsing * CVE-2026-4684 Race condition, use-after-free in the Graphics: WebRender component * CVE-2026-4685 Incorrect boundary conditions in the Graphics: Canvas2D component * CVE-2026-4686 Incorrect boundary conditions in the Graphics: Canvas2D component * CVE-2026-4687 Sandbox escape due to incorrect boundary conditions in the Telemetry component * CVE-2026-4688 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-4689 Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component * CVE-2026-4690 Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component * CVE-2026-4691 Use-after-free in the CSS Parsing and Computation component * CVE-2026-4692 Sandbox escape in the Responsive Design Mode component * CVE-2026-4693 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-4694 Incorrect boundary conditions, integer overflow in the Graphics component * CVE-2026-4695 Incorrect boundary conditions in the Audio/Video: Web Codecs component * CVE-2026-4696 Use-after-free in the Layout: Text and Fonts component * CVE-2026-4697 Incorrect boundary conditions in the Audio/Video: Web Codecs component * CVE-2026-4698 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-4699 Incorrect boundary conditions in the Layout: Text and Fonts component * CVE-2026-4700 Mitigation bypass in the Networking: HTTP component * CVE-2026-4701 Use-after-free in the JavaScript Engine component * CVE-2026-4702 JIT miscompilation in the JavaScript Engine component * CVE-2026-4704 Denial-of-service in the WebRTC: Signaling component * CVE-2026-4705 Undefined behavior in the WebRTC: Signaling component * CVE-2026-4706 Incorrect boundary conditions in the Graphics: Canvas2D component * CVE-2026-4707 Incorrect boundary conditions in the Graphics: Canvas2D component * CVE-2026-4708 Incorrect boundary conditions in the Graphics component * CVE-2026-4709 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-4710 Incorrect boundary conditions in the Audio/Video component * CVE-2026-4711 Use-after-free in the Widget: Cocoa component * CVE-2026-4712 Information disclosure in the Widget: Cocoa component * CVE-2026-4713 Incorrect boundary conditions in the Graphics component * CVE-2026-4714 Incorrect boundary conditions in the Audio/Video component * CVE-2026-4715 Uninitialized memory in the Graphics: Canvas2D component * CVE-2026-4716 Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component * CVE-2026-4717 Privilege escalation in the Netmonitor component * CVE-2025-59375 Denial-of-service in the XML component * CVE-2026-4718 Undefined behavior in the WebRTC: Signaling component * CVE-2026-4719 Incorrect boundary conditions in the Graphics: Text component * CVE-2026-4720 Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 * CVE-2026-4721 Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1260083
- https://bugzilla.suse.com/1262230
- https://www.suse.com/security/cve/CVE-2025-59375
- https://www.suse.com/security/cve/CVE-2026-3889
- https://www.suse.com/security/cve/CVE-2026-4371
- https://www.suse.com/security/cve/CVE-2026-4684
- https://www.suse.com/security/cve/CVE-2026-4685
- https://www.suse.com/security/cve/CVE-2026-4686
- https://www.suse.com/security/cve/CVE-2026-4687
- https://www.suse.com/security/cve/CVE-2026-4688
- https://www.suse.com/security/cve/CVE-2026-4689
- https://www.suse.com/security/cve/CVE-2026-4690
- https://www.suse.com/security/cve/CVE-2026-4691
- https://www.suse.com/security/cve/CVE-2026-4692
- https://www.suse.com/security/cve/CVE-2026-4693
- https://www.suse.com/security/cve/CVE-2026-4694
- https://www.suse.com/security/cve/CVE-2026-4695
- https://www.suse.com/security/cve/CVE-2026-4696
- https://www.suse.com/security/cve/CVE-2026-4697
- https://www.suse.com/security/cve/CVE-2026-4698
- https://www.suse.com/security/cve/CVE-2026-4699
- https://www.suse.com/security/cve/CVE-2026-4700
- https://www.suse.com/security/cve/CVE-2026-4701
- https://www.suse.com/security/cve/CVE-2026-4702
- https://www.suse.com/security/cve/CVE-2026-4704
- https://www.suse.com/security/cve/CVE-2026-4705
- https://www.suse.com/security/cve/CVE-2026-4706
- https://www.suse.com/security/cve/CVE-2026-4707
- https://www.suse.com/security/cve/CVE-2026-4708
- https://www.suse.com/security/cve/CVE-2026-4709
- https://www.suse.com/security/cve/CVE-2026-4710
- https://www.suse.com/security/cve/CVE-2026-4711
- https://www.suse.com/security/cve/CVE-2026-4712
- https://www.suse.com/security/cve/CVE-2026-4713
- https://www.suse.com/security/cve/CVE-2026-4714
- https://www.suse.com/security/cve/CVE-2026-4715
- https://www.suse.com/security/cve/CVE-2026-4716
- https://www.suse.com/security/cve/CVE-2026-4717
- https://www.suse.com/security/cve/CVE-2026-4718
- https://www.suse.com/security/cve/CVE-2026-4719
- https://www.suse.com/security/cve/CVE-2026-4720
- https://www.suse.com/security/cve/CVE-2026-4721
- https://www.suse.com/security/cve/CVE-2026-5731
- https://www.suse.com/security/cve/CVE-2026-5732
- https://www.suse.com/security/cve/CVE-2026-5734
- https://www.suse.com/security/cve/CVE-2026-6746
- https://www.suse.com/security/cve/CVE-2026-6747
- https://www.suse.com/security/cve/CVE-2026-6748
- https://www.suse.com/security/cve/CVE-2026-6749
- https://www.suse.com/security/cve/CVE-2026-6750
- https://www.suse.com/security/cve/CVE-2026-6751
- https://www.suse.com/security/cve/CVE-2026-6752
- https://www.suse.com/security/cve/CVE-2026-6753
- https://www.suse.com/security/cve/CVE-2026-6754
- https://www.suse.com/security/cve/CVE-2026-6757
- https://www.suse.com/security/cve/CVE-2026-6759
- https://www.suse.com/security/cve/CVE-2026-6761
- https://www.suse.com/security/cve/CVE-2026-6762
- https://www.suse.com/security/cve/CVE-2026-6763
- https://www.suse.com/security/cve/CVE-2026-6764
- https://www.suse.com/security/cve/CVE-2026-6765
- https://www.suse.com/security/cve/CVE-2026-6766
- https://www.suse.com/security/cve/CVE-2026-6767
- https://www.suse.com/security/cve/CVE-2026-6769
- https://www.suse.com/security/cve/CVE-2026-6770
- https://www.suse.com/security/cve/CVE-2026-6771
- https://www.suse.com/security/cve/CVE-2026-6772
- https://www.suse.com/security/cve/CVE-2026-6776
- https://www.suse.com/security/cve/CVE-2026-6785
- https://www.suse.com/security/cve/CVE-2026-6786