﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
21998	thunderbird-140.2.0esr	Joe Locash	Douglas R. Reno	"**What’s Fixed**
 - Users were unable to use Fastmail calendars due to missing OAuth settings
 - Account setup error handling was broken for Account hub
 - Menu bar was hidden after updating from 128esr to 140esr

**Security fixes**
https://www.mozilla.org/en-US/security/advisories/mfsa2025-72/

 - CVE-2025-9179: Sandbox escape due to invalid pointer in the Audio/Video: GMP component (high)
 - CVE-2025-9180: Same-origin policy bypass in the Graphics: Canvas2D component
(high)
 - CVE-2025-9181: Uninitialized memory in the JavaScript Engine component (moderate)
 - CVE-2025-9182: Denial-of-service due to out-of-memory in the Graphics: WebRender component (low)
 - CVE-2025-9184: Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 (high)
 - CVE-2025-9185: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142 (high)
"	enhancement	closed	high	12.4	BOOK	git	medium	fixed		
