BlackTreeCVE IntelligenceOfficial source evidencewww.mozilla.orgVersioned article
Official source article · www.mozilla.org
Security Vulnerabilities fixed in Thunderbird 152 — Mozilla
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisherwww.mozilla.org
Article IDNo stable ID in source URL
Verified snapshot29 Sept 2026, 08:14 UTC
Linked CVEs40
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-12328Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
- CVE-2026-12299JIT miscompilation in the DOM: Core & HTML component
- CVE-2026-12298Memory safety bug fixed in Firefox 152
- CVE-2026-12297Sandbox escape due to incorrect boundary conditions in the Networking component
- CVE-2026-12296Sandbox escape in the Security: Process Sandboxing component
- CVE-2026-12295Sandbox escape in the DOM: Navigation component
- CVE-2026-12294Sandbox escape in the DOM: Workers component
- CVE-2026-12292Incorrect boundary conditions in the Web Audio component
- CVE-2026-12291Use-after-free in the Networking: HTTP component
- CVE-2026-12290Memory safety bug fixed in Firefox 152
- CVE-2026-12289Privilege escalation in the Graphics: WebRender component
- CVE-2026-12293Use-after-free in the Graphics: WebGPU component
- CVE-2026-12326Memory safety bugs fixed in Firefox 152 and Thunderbird 152
- CVE-2026-12322Clickjacking issue in the Widget: Gtk component
- CVE-2026-12317Memory safety bug fixed in Firefox 152
- CVE-2026-12314Memory safety bug fixed in Firefox 152
- CVE-2026-12312Memory safety bug fixed in Firefox 152
- CVE-2026-12310Memory safety bug fixed in Firefox 152
- CVE-2026-12309Memory safety bug fixed in Firefox 152
- CVE-2026-12308Memory safety bug fixed in Firefox 152
- CVE-2026-12307Memory safety bug fixed in Firefox 152
- CVE-2026-12306Memory safety bug fixed in Firefox 152
- CVE-2026-12305Memory safety bug fixed in Firefox 152
- CVE-2026-12301Memory safety bug fixed in Firefox 152
- CVE-2026-12300Memory safety bug fixed in Firefox 152
- CVE-2026-12327Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
- CVE-2026-12304Same-origin policy bypass in the Networking: Cookies component
- CVE-2026-12315Mitigation bypass in the DOM: Security component
- CVE-2026-12316Mitigation bypass in the DOM: Security component
- CVE-2026-12318Incorrect boundary conditions in the Libraries component in NSS
- CVE-2026-12302Mitigation bypass in the DOM: Security component
- CVE-2026-12324Incorrect boundary conditions in the Graphics: CanvasWebGL component
- CVE-2026-12325Denial-of-service in the Graphics: ImageLib component
- CVE-2026-12323Spoofing issue in the DOM: Core & HTML component
- CVE-2026-12321JIT miscompilation in the JavaScript: WebAssembly component
- CVE-2026-12320Information disclosure in the Password Manager component
- CVE-2026-12319Denial-of-service in the Audio/Video: Playback component
- CVE-2026-12313Information disclosure, sandbox escape in the Security: Process Sandboxing component
- CVE-2026-12311Information disclosure, sandbox escape in the Security: Process Sandboxing component
- CVE-2026-12303Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component
Source and provenance
Original title: Security Vulnerabilities fixed in Thunderbird 152 — Mozilla. Captured 29 Sept 2026, 08:14 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗