MGASA-2026-0388

    Dashboard / Vulnerabilities / MGASA-2026-0388

    MGASA-2026-0388

    Published: 9 Sept 2026Last Modified: 9 Sept 2026

    Summary: Updated thunderbird packages fix security vulnerabilities

    Details: Uninitialized memory in MIME parsing. (CVE-2026-84639) One byte overflow read in mail parser. (CVE-2026-84640) Information disclosure due to malicious IMAP server response. (CVE-2026-84641) Calendar invitation attachments could launch local executables. (CVE-2026-84637) Allowed UNC hostnames for attachments interpreted as a regular expression. (CVE-2026-84642) Sandbox escape in the Remote Settings Client component. (CVE-2026-75874) Privilege escalation in the DOM: Workers component. (CVE-2026-16365) Use-after-free in the JavaScript: GC component. (CVE-2026-84118) Sandbox escape due to use-after-free in the DOM: Navigation component. (CVE-2026-84119) Use-after-free in the Audio/Video component. (CVE-2026-84120) Sandbox escape due to use-after-free in the DOM: Security component. (CVE-2026-84121) Use-after-free in the Audio/Video component. (CVE-2026-84122) Privilege escalation due to use-after-free in the Graphics: WebGPU component. (CVE-2026-84123) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84124) Use-after-free in the DOM: Core & HTML component. (CVE-2026-84125) Privilege escalation in the DOM: Navigation component. (CVE-2026-16371) Privilege escalation in the Application Update component. (CVE-2026-74952) Site isolation issue in the DOM: Navigation component. (CVE-2026-84129) Information disclosure in the Graphics: WebGPU component. (CVE-2026-84130) Privilege escalation due to invalid pointer in the Graphics component. (CVE-2026-84131) Information disclosure in the Networking: HTTP component. (CVE-2026-84132) Site isolation issue in the DOM: Push Subscriptions component. (CVE-2026-84133) Other issue in the Profile Backup component. (CVE-2026-84134) Other issue in the DOM: Navigation component. (CVE-2026-84136) Spoofing issue in the DOM: Core & HTML component. (CVE-2026-84137) Clickjacking issue in the DOM: Events component. (CVE-2026-84139) Site isolation issue in the DOM: Navigation component. (CVE-2026-84140) Integer overflow in the Graphics: ImageLib component. (CVE-2026-84141) Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15. (CVE-2026-84143) Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2. (CVE-2026-84144) Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15. (CVE-2026-84145)

    Affected packages

    Package

    Name: thunderbird

    Purl: pkg:rpm/mageia/thunderbird?arch=source&distro=mageia-10

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -153.2.0-1.mga10

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    MGASA-2026-0388 | CVE-DB