Description: Mitigation bypass in the DOM: Security component. (CVE-2026-0877) Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. (CVE-2026-0878) Sandbox escape due to incorrect boundary conditions in the Graphics component. (CVE-2026-0879) Sandbox escape due to integer overflow in the Graphics component. (CVE-2026-0880) Use-after-free in the IPC component. (CVE-2026-0882) Spoofing issue in the Downloads Panel component. (CVE-2025-14327) Information disclosure in the Networking component. (CVE-2026-0883) Use-after-free in the JavaScript Engine component. (CVE-2026-0884) Use-after-free in the JavaScript: GC component. (CVE-2026-0885) Incorrect boundary conditions in the Graphics component. (CVE-2026-0886) Clickjacking issue, information disclosure in the PDF Viewer component. (CVE-2026-0887) Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. (CVE-2026-0890) Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, F...
- https://bugs.mageia.org/show_bug.cgi?id=34993
- https://www.thunderbird.net/en-US/thunderbird/140.7.0esr/releasenotes/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-05/
- https://www.cve.org/CVERecord?id=CVE-2026-0877
- https://www.cve.org/CVERecord?id=CVE-2026-0878
- https://www.cve.org/CVERecord?id=CVE-2026-0879
- https://www.cve.org/CVERecord?id=CVE-2026-0880
- https://www.cve.org/CVERecord?id=CVE-2026-0882
- https://www.cve.org/CVERecord?id=CVE-2025-14327
- https://www.cve.org/CVERecord?id=CVE-2026-0883
- https://www.cve.org/CVERecord?id=CVE-2026-0884
- https://www.cve.org/CVERecord?id=CVE-2026-0885
- https://www.cve.org/CVERecord?id=CVE-2026-0886
- https://www.cve.org/CVERecord?id=CVE-2026-0887
- https://www.cve.org/CVERecord?id=CVE-2026-0890
- https://www.cve.org/CVERecord?id=CVE-2026-0891
- 9/core/thunderbird-140.7.0-1.mga9
- 9/core/thunderbird-l10n-140.7.0-1.mga9
Get the latest Linux and open source security news straight to your inbox.