thunderbird:sid, firefox-esr:sid is vulnerable to Return-Oriented Programming(ROP). The vulnerability is due to improper handling of return registers, potentially allowing attackers to execute arbitrary code by overwriting them with controlled values.
bugzilla.mozilla.org/show_bug.cgi?id=1879939
lists.debian.org/debian-lts-announce/2024/03/msg00022.html
lists.debian.org/debian-lts-announce/2024/03/msg00028.html
security-tracker.debian.org/tracker/CVE-2024-2607
www.mozilla.org/security/advisories/mfsa2024-12/
www.mozilla.org/security/advisories/mfsa2024-13/
www.mozilla.org/security/advisories/mfsa2024-14/