﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
22826	Backport the fix for CVE-2026-2447 to seamonkey	Douglas R. Reno	zeckma	"Both Thunderbird and Firefox got emergency updates for a high severity heap buffer overflow problem in libvpx. We use the system copy for both of those packages, so we in theory shouldn't be affected by those unless a user didn't install the recommended dependencies (which is certainly possible and part of why we should be doing those anyway)

On the other hand, Seamonkey does use the bundled copy of libvpx, so it's directly impacted by this issue. It looks like a remote code execution rated as 8.8 High, and can be triggered via video playback. Note though that some sites use autoplay and a user can thus get hit by this vulnerability through normal browsing activities.

"	enhancement	closed	high	13.0	BOOK	git	medium	fixed		
