Security Vulnerabilities fixed in Mozilla Thunderbird 91.3. Thunderbird is a standalone mail and newsgroup client.
In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
The update upgrades Thunderbird to version 91.3.0.
⚠️ Mozilla: Use-after-free in HTTP2 Session object
⚠️ Mozilla: Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3
⚠️ Mozilla: iframe sandbox rules did not apply to XSLT stylesheets (CVE-2021-38503)
⚠️ Mozilla: Use-after-free in file picker dialog (CVE-2021-38504)
⚠️ Mozilla: Firefox could be coaxed into going into fullscreen mode without notification or warning (CVE-2021-38506)
⚠️ Mozilla: Opportunistic Encryption in HTTP2 could be used to bypass the Same-Origin-Policy on services hosted on other ports (CVE-2021-38507)
⚠️ Mozilla: Permission Prompt could be overlaid, resulting in user confusion and potential spoofing (CVE-2021-38508)