﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
22148	thunderbird-140.3.0esr	Joe Locash	zeckma	"**What’s Fixed**
 - Right-clicking 'List-ID' -> 'Unsubscribe' created double encoded draft subject
 - Thunderbird could crash on startup
 - Thunderbird could crash when importing mail
 - Opening Website header link in RSS feed incorrectly re-encoded URL parameters

**Security fixes**

https://www.mozilla.org/en-US/security/advisories/mfsa2025-78/

 - CVE-2025-10527: Sandbox escape due to use-after-free in the Graphics: Canvas2D component (high)
 - CVE-2025-10528: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component (high)
 - CVE-2025-10529: Same-origin policy bypass in the Layout component (moderate)
 - CVE-2025-10532: Incorrect boundary conditions in the JavaScript: GC component (moderate)
 - CVE-2025-10533: Integer overflow in the SVG component (moderate)
 - CVE-2025-10536: Information disclosure in the Networking: Cache component (low)
 - CVE-2025-10537: Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143 (high)

"	enhancement	closed	high	13.0	BOOK	git	medium	fixed		
