CVE-2026-12318:
Incorrect boundary conditions in the Libraries component in NSS. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
Standards version of the package is outdated.
high
The package is severely out of date with respect to the Debian Policy.The package should be updated to follow the last version of Debian Policy
(Standards-Version 4.7.4 instead of
3.9.8.0).
You should get rid of them to provide more metadata about this software.
debian/patches: 17 patches to forward upstream
low
Among the 17 debian patches
available in version 152.0.3-1 of the package,
we noticed the following issues:
17 patches
where the metadata indicates that the patch has not yet been forwarded
upstream. You should either forward the patch upstream or update the
metadata to document its real status.