| Name | DSA-6481-1 |
| Description | firefox-esr - security update |
| Source | Debian |
| References | CVE-2026-16365, CVE-2026-16371, CVE-2026-75874, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84124, CVE-2026-84131, CVE-2026-84143, CVE-2026-84145 |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| firefox-esr (PTS) | trixie | 140.12.0esr-1~deb13u1 | vulnerable |
| trixie (security) | 140.14.0esr-1~deb13u1 | vulnerable |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| firefox-esr | source | trixie | 140.15.0esr-1~deb13u1 | | | |