Cross-origin information leakage via redirected PDF requests. (CVE-2021-23953)
Type confusion when using logical assignment operators in JavaScript switch statements. (CVE-2021-23954)
IMAP Response Injection when using STARTTLS. (CVE-2020-15685)
HTTPS pages could have been intercepted by a registered service worker when they should not have been. (CVE-2020-26976)
Use-after-poison for incorrectly redeclared JavaScript variables during GC. (CVE-2021-23960)
Memory safety bugs fixed in Thunderbird 78.7. (CVE-2021-23964).