﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
21655	thunderbird-128.11.0esr	Douglas R. Reno	Douglas R. Reno	"New minor version. Because I need to do some SA updates anyway I'll get this one in today

**Release notes:**

What's Fixed?

- Thunderbird could crash if message copying to Sent folder was interrupted
- Security fixes

**Security fixes:**

- CVE-2025-5262: Double-free in libvpx encoder (Critical)
- CVE-2025-5263: Error handling for script execution was incorrectly isolated from web content (Moderate)
- CVE-2025-5264: Potential local code execution in “Copy as cURL” command (Moderate)
- CVE-2025-5266: Script element events leaked cross-origin resource status (Moderate)
- CVE-2025-5267: Clickjacking vulnerability could have led to leaking saved payment card details (Low)
- CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11 (Moderate)
- CVE-2025-5269: Memory safety bug fixed in Firefox ESR 128.11 and Thunderbird 128.11 (Moderate)"	enhancement	closed	high	12.4	BOOK	git	medium	fixed		
