<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for MozillaThunderbird</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2024:4050-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-11-25T15:37:44Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-11-25T15:37:44Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-11-25T15:37:44Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for MozillaThunderbird</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for MozillaThunderbird fixes the following issues:

- Mozilla Thunderbird 128.4.3
  * fixed: Folder corruption could cause Thunderbird to freeze
    and become unusable
  * fixed: Message corruption could be propagated when reading mbox
  * fixed: Folder compaction was not abandoned on shutdown
  * fixed: Folder compaction did not clean up on failure
  * fixed: Collapsed NNTP thread incorrectly indicated there were
    unread messages
  * fixed: Navigating to next unread message did not wait for all
    messages to be loaded
  * fixed: Applying column view to folder and children could
    break if folder error occurred
  * fixed: Remote content notifications were broken with
    encrypted messages
  * fixed: Updating criteria of a saved search resulted in poor
    search performance
  * fixed: Drop-downs may not work in some places
  * fixed: Security fixes
  MFSA 2024-61 (bsc#1233355)
  * CVE-2024-11159 Potential disclosure of plaintext in OpenPGP encrypted message

- Mozilla Thunderbird 128.4.2
  * changed: Increased the auto-compaction threshold to reduce
    frequency of compaction
  * fixed: New profile creation caused console errors
  * fixed: Repair folder could result in older messages showing
    wrong date and time
  * fixed: Recently deleted messages could become undeleted if
    message compaction failed
  * fixed: Visual and UX improvements
  * fixed: Clicking on an HTML button could cause Thunderbird to freeze
  * fixed: Messages could not be selected for dragging
  * fixed: Could not open attached file in a MIME encrypted message
  * fixed: Account creation 'Setup Documentation' link was broken
  * fixed: Unable to generate QR codes when exporting to mobile
    in some cases
  * fixed: Operating system reauthentication was missing when
    exporting QR codes for mobile
  * fixed: Could not drag all-day events from one day to another
    in week view

- Mozilla Thunderbird 128.4.1
  * new: Add the 20 year donation appeal

- Mozilla Thunderbird 128.4
  * new: Export Thunderbird account settings to Thunderbird
    Mobile via QRCode
  * fixed: Unable to send an unencrypted response to an OpenPGP
    encrypted message
  * fixed: Thunderbird update did not update language pack
    version until another restart
  * fixed: Security fixes
  MFSA 2024-58 (bsc#1231879)
  * CVE-2024-10458 Permission leak via embed or object elements
  * CVE-2024-10459 Use-after-free in layout with accessibility
  * CVE-2024-10460 Confusing display of origin for external protocol handler prompt
  * CVE-2024-10461 XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response
  * CVE-2024-10462 Origin of permission prompt could be spoofed by long URL
  * CVE-2024-10463 Cross origin video frame leak
  * CVE-2024-10464 History interface could have been used to cause a Denial of Service condition in the browser
  * CVE-2024-10465 Clipboard 'paste' button persisted across tabs
  * CVE-2024-10466 DOM push subscription message could hang Firefox
  * CVE-2024-10467 Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2024-4050,SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-4050,SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-4050,SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-4050,SUSE-SLE-Product-WE-15-SP5-2024-4050,SUSE-SLE-Product-WE-15-SP6-2024-4050,openSUSE-SLE-15.5-2024-4050,openSUSE-SLE-15.6-2024-4050</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      <Description>Link for SUSE-SU-2024:4050-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-security-updates/2024-November/019842.html</URL>
      <Description>E-Mail link for SUSE-SU-2024:4050-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1231879</URL>
      <Description>SUSE Bug 1231879</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1233355</URL>
      <Description>SUSE Bug 1233355</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10458/</URL>
      <Description>SUSE CVE CVE-2024-10458 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10459/</URL>
      <Description>SUSE CVE CVE-2024-10459 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10460/</URL>
      <Description>SUSE CVE CVE-2024-10460 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10461/</URL>
      <Description>SUSE CVE CVE-2024-10461 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10462/</URL>
      <Description>SUSE CVE CVE-2024-10462 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10463/</URL>
      <Description>SUSE CVE CVE-2024-10463 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10464/</URL>
      <Description>SUSE CVE CVE-2024-10464 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10465/</URL>
      <Description>SUSE CVE CVE-2024-10465 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10466/</URL>
      <Description>SUSE CVE CVE-2024-10466 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-10467/</URL>
      <Description>SUSE CVE CVE-2024-10467 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-11159/</URL>
      <Description>SUSE CVE CVE-2024-11159 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Package Hub 15 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5" CPE="cpe:/o:suse:packagehub:15:sp5">SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Package Hub 15 SP6">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6" CPE="cpe:/o:suse:packagehub:15:sp6">SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Workstation Extension 15 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15 SP5">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP5" CPE="cpe:/o:suse:sle-we:15:sp5">SUSE Linux Enterprise Workstation Extension 15 SP5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Workstation Extension 15 SP6">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Workstation Extension 15 SP6">
        <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP6" CPE="cpe:/o:suse:sle-we:15:sp6">SUSE Linux Enterprise Workstation Extension 15 SP6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.5">
      <Branch Type="Product Name" Name="openSUSE Leap 15.5">
        <FullProductName ProductID="openSUSE Leap 15.5" CPE="cpe:/o:opensuse:leap:15.5">openSUSE Leap 15.5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.6">
      <Branch Type="Product Name" Name="openSUSE Leap 15.6">
        <FullProductName ProductID="openSUSE Leap 15.6" CPE="cpe:/o:opensuse:leap:15.6">openSUSE Leap 15.6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="MozillaThunderbird-128.4.3-150200.8.188.1">
      <FullProductName ProductID="MozillaThunderbird-128.4.3-150200.8.188.1">MozillaThunderbird-128.4.3-150200.8.188.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="MozillaThunderbird-translations-common-128.4.3-150200.8.188.1">
      <FullProductName ProductID="MozillaThunderbird-translations-common-128.4.3-150200.8.188.1">MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="MozillaThunderbird-translations-other-128.4.3-150200.8.188.1">
      <FullProductName ProductID="MozillaThunderbird-translations-other-128.4.3-150200.8.188.1">MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</FullProductName>
    </Branch>
    <Relationship ProductReference="MozillaThunderbird-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1">MozillaThunderbird-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-common-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1">MozillaThunderbird-translations-common-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-other-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1">MozillaThunderbird-translations-other-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Module for Package Hub 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1">MozillaThunderbird-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-common-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1">MozillaThunderbird-translations-common-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-other-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Package Hub 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1">MozillaThunderbird-translations-other-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Module for Package Hub 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1">MozillaThunderbird-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Workstation Extension 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-common-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1">MozillaThunderbird-translations-common-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Workstation Extension 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-other-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP5">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1">MozillaThunderbird-translations-other-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Workstation Extension 15 SP5</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1">MozillaThunderbird-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Workstation Extension 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-common-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1">MozillaThunderbird-translations-common-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Workstation Extension 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-other-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Workstation Extension 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1">MozillaThunderbird-translations-other-128.4.3-150200.8.188.1 as a component of SUSE Linux Enterprise Workstation Extension 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1">MozillaThunderbird-128.4.3-150200.8.188.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-common-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1">MozillaThunderbird-translations-common-128.4.3-150200.8.188.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-other-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.5">
      <FullProductName ProductID="openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1">MozillaThunderbird-translations-other-128.4.3-150200.8.188.1 as a component of openSUSE Leap 15.5</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1">MozillaThunderbird-128.4.3-150200.8.188.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-common-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1">MozillaThunderbird-translations-common-128.4.3-150200.8.188.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-other-128.4.3-150200.8.188.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1">MozillaThunderbird-translations-other-128.4.3-150200.8.188.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Firefox ESR &lt; 115.17, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10458</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10458.html</URL>
        <Description>CVE-2024-10458</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Firefox ESR &lt; 115.17, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10459</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10459.html</URL>
        <Description>CVE-2024-10459</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10460</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10460.html</URL>
        <Description>CVE-2024-10460</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10461</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10461.html</URL>
        <Description>CVE-2024-10461</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10462</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10462.html</URL>
        <Description>CVE-2024-10462</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Firefox ESR &lt; 115.17, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10463</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10463.html</URL>
        <Description>CVE-2024-10463</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10464</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10464.html</URL>
        <Description>CVE-2024-10464</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10465</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10465.html</URL>
        <Description>CVE-2024-10465</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10466</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10466.html</URL>
        <Description>CVE-2024-10466</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox &lt; 132, Firefox ESR &lt; 128.4, Thunderbird &lt; 128.4, and Thunderbird &lt; 132.</Note>
    </Notes>
    <CVE>CVE-2024-10467</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-10467.html</URL>
        <Description>CVE-2024-10467</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1231879</URL>
        <Description>SUSE Bug 1231879</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird &lt; 128.4.3 and Thunderbird &lt; 132.0.1.</Note>
    </Notes>
    <CVE>CVE-2024-11159</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Package Hub 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>SUSE Linux Enterprise Workstation Extension 15 SP6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.5:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-common-128.4.3-150200.8.188.1</ProductID>
        <ProductID>openSUSE Leap 15.6:MozillaThunderbird-translations-other-128.4.3-150200.8.188.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20244050-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-11159.html</URL>
        <Description>CVE-2024-11159</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1233355</URL>
        <Description>SUSE Bug 1233355</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
