This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird 128.2.3 MFSA 2024-43 (bsc#1229821) CVE-2024-8394: Crash when aborting verification of OTR chat. CVE-2024-8385: WASM type confusion involving ArrayTypes. CVE-2024-8381: Type confusion when looking up a property name in a 'with' block. CVE-2024-8382: Internal event interfaces were exposed to web content when browser EventHandler listener callbacks ran. CVE-2024-8384: Garbage collection could mis-color cross-compartment objects in OOM conditions. CVE-2024-8386: SelectElements could be shown over another site if popups are allowed. CVE-2024-8387: Memory safety bugs fixed in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. MFSA 2024-37 (bsc#1228648) CVE-2024-7518: Fullscreen notification dialog can be obscured by document content. CVE-2024-7519: Out of bounds memory access in graphics shared memory handling. CVE-2024-7520: Type confusion in WebAssembly. CVE-2024-7521: Incomplete WebAssembly exception handing. CVE-2024-7522: Out of bounds read in editor component. CVE-2024-7525: Missing permission check when creating a StreamFilter. CVE-2024-7526: Uninitialized memory used by WebGL. CVE-2024-7527: Use-after-free in JavaScript garbage collection. CVE-2024-7528: Use-after-free in IndexedDB. CVE-2024-7529: Document content could partially obscure security prompts. MFSA 2024-32 (bsc#1226316) CVE-2024-6606: Out-of-bounds read in clipboard component. CVE-2024-6607: Leaving pointerlock by…Read More
