﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
23111	firefox-140.11.0esr and js-140.11.0 (spidermonkey)		SecurityAdvisory	"New point version

This includes three high severity security fixes.

- CVE-2026-5732: Incorrect boundary conditions, integer overflow in the Graphics: Text component (High)
- CVE-2026-5731: Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (High). Description: ""Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.""
- CVE-2026-5734: Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 (High). Description: ""Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.""

I discussed this and a couple of other problems with Zeckma earlier this morning. She's going to be taking a break for a couple days since it's her first day off from her job for a while. I will take care of this as a result and will aim to have it in as soon as I can."	enhancement	closed	high	13.1	BOOK	git	medium	fixed		
