Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| red_hat_enterprise_linux_6:firefox firefox as a component of Red Hat Enterprise Linux 6 | affected | no version stated vendor label: firefox | out of support fix in another branch | csaf_redhat | |
| red_hat_enterprise_linux_6:firefox.src firefox.src as a component of Red Hat Enterprise Linux 6 | affected | no version stated vendor label: firefox.src | out of support fix in another branch | csaf_redhat | |
| red_hat_enterprise_linux_6:thunderbird thunderbird as a component of Red Hat Enterprise Linux 6 | affected | no version stated vendor label: thunderbird | out of support fix in another branch | csaf_redhat | |
| red_hat_enterprise_linux_7:thunderbird thunderbird as a component of Red Hat Enterprise Linux 7 | affected | no version stated vendor label: thunderbird | out of support fix in another branch | csaf_redhat | |
| red_hat_enterprise_linux_6:thunderbird.src thunderbird.src as a component of Red Hat Enterprise Linux 6 | affected | no version stated vendor label: thunderbird.src | out of support fix in another branch | csaf_redhat | |
| red_hat_enterprise_linux_7:thunderbird.src thunderbird.src as a component of Red Hat Enterprise Linux 7 | affected | no version stated vendor label: thunderbird.src | out of support fix in another branch | csaf_redhat | |
| 7Server-ELS:firefox-0:128.3.1-2.el7_9.s390x firefox-0:128.3.1-2.el7_9.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS) | fixed | firefox-0:128.3.1-2.el7_9.s390x | vendor fix → firefox-0:128.3.1-2.el7_9.s390x (RHSA-2024:8034) | csaf_redhat | |
| 7Server-ELS:firefox-0:128.3.1-2.el7_9.src firefox-0:128.3.1-2.el7_9.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS) | fixed | firefox-0:128.3.1-2.el7_9.src | vendor fix → firefox-0:128.3.1-2.el7_9.src (RHSA-2024:8034) | csaf_redhat | |
| 7Server-ELS:firefox-0:128.3.1-2.el7_9.x86_64 firefox-0:128.3.1-2.el7_9.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS) | fixed | firefox-0:128.3.1-2.el7_9.x86_64 | vendor fix → firefox-0:128.3.1-2.el7_9.x86_64 (RHSA-2024:8034) | csaf_redhat | |
| AppStream-8.10.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el8_10.aarch64 firefox-0:128.3.1-2.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8) | fixed | firefox-0:128.3.1-2.el8_10.aarch64 | vendor fix → firefox-0:128.3.1-2.el8_10.aarch64 (RHSA-2024:7977) | csaf_redhat | |
| AppStream-8.10.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el8_10.ppc64le firefox-0:128.3.1-2.el8_10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8) | fixed | firefox-0:128.3.1-2.el8_10.ppc64le | vendor fix → firefox-0:128.3.1-2.el8_10.ppc64le (RHSA-2024:7977) | csaf_redhat | |
| AppStream-8.10.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el8_10.s390x firefox-0:128.3.1-2.el8_10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8) | fixed | firefox-0:128.3.1-2.el8_10.s390x | vendor fix → firefox-0:128.3.1-2.el8_10.s390x (RHSA-2024:7977) | csaf_redhat | |
| AppStream-8.10.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el8_10.src firefox-0:128.3.1-2.el8_10.src as a component of Red Hat Enterprise Linux AppStream (v. 8) | fixed | firefox-0:128.3.1-2.el8_10.src | vendor fix → firefox-0:128.3.1-2.el8_10.src (RHSA-2024:7977) | csaf_redhat | |
| AppStream-8.10.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el8_10.x86_64 firefox-0:128.3.1-2.el8_10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8) | fixed | firefox-0:128.3.1-2.el8_10.x86_64 | vendor fix → firefox-0:128.3.1-2.el8_10.x86_64 (RHSA-2024:7977) | csaf_redhat | |
| AppStream-8.2.0.Z.AUS:firefox-0:128.3.1-2.el8_2.src firefox-0:128.3.1-2.el8_2.src as a component of Red Hat Enterprise Linux AppStream AUS (v. 8.2) | fixed | firefox-0:128.3.1-2.el8_2.src | vendor fix → firefox-0:128.3.1-2.el8_2.src (RHSA-2024:8176) | csaf_redhat | |
| AppStream-8.2.0.Z.AUS:firefox-0:128.3.1-2.el8_2.x86_64 firefox-0:128.3.1-2.el8_2.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v. 8.2) | fixed | firefox-0:128.3.1-2.el8_2.x86_64 | vendor fix → firefox-0:128.3.1-2.el8_2.x86_64 (RHSA-2024:8176) | csaf_redhat | |
| AppStream-8.4.0.Z.E4S:firefox-0:128.3.1-2.el8_4.ppc64le firefox-0:128.3.1-2.el8_4.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.8.4) | fixed | firefox-0:128.3.1-2.el8_4.ppc64le | vendor fix → firefox-0:128.3.1-2.el8_4.ppc64le (RHSA-2024:8167) | csaf_redhat | |
| AppStream-8.4.0.Z.AUS:firefox-0:128.3.1-2.el8_4.src firefox-0:128.3.1-2.el8_4.src as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4) | fixed | firefox-0:128.3.1-2.el8_4.src | vendor fix → firefox-0:128.3.1-2.el8_4.src (RHSA-2024:8167) | csaf_redhat | |
| AppStream-8.4.0.Z.E4S:firefox-0:128.3.1-2.el8_4.src firefox-0:128.3.1-2.el8_4.src as a component of Red Hat Enterprise Linux AppStream E4S (v.8.4) | fixed | firefox-0:128.3.1-2.el8_4.src | vendor fix → firefox-0:128.3.1-2.el8_4.src (RHSA-2024:8167) | csaf_redhat | |
| AppStream-8.4.0.Z.TUS:firefox-0:128.3.1-2.el8_4.src firefox-0:128.3.1-2.el8_4.src as a component of Red Hat Enterprise Linux AppStream TUS (v.8.4) | fixed | firefox-0:128.3.1-2.el8_4.src | vendor fix → firefox-0:128.3.1-2.el8_4.src (RHSA-2024:8167) | csaf_redhat | |
| AppStream-8.4.0.Z.AUS:firefox-0:128.3.1-2.el8_4.x86_64 firefox-0:128.3.1-2.el8_4.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4) | fixed | firefox-0:128.3.1-2.el8_4.x86_64 | vendor fix → firefox-0:128.3.1-2.el8_4.x86_64 (RHSA-2024:8167) | csaf_redhat | |
| AppStream-8.4.0.Z.E4S:firefox-0:128.3.1-2.el8_4.x86_64 firefox-0:128.3.1-2.el8_4.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.4) | fixed | firefox-0:128.3.1-2.el8_4.x86_64 | vendor fix → firefox-0:128.3.1-2.el8_4.x86_64 (RHSA-2024:8167) | csaf_redhat | |
| AppStream-8.4.0.Z.TUS:firefox-0:128.3.1-2.el8_4.x86_64 firefox-0:128.3.1-2.el8_4.x86_64 as a component of Red Hat Enterprise Linux AppStream TUS (v.8.4) | fixed | firefox-0:128.3.1-2.el8_4.x86_64 | vendor fix → firefox-0:128.3.1-2.el8_4.x86_64 (RHSA-2024:8167) | csaf_redhat | |
| AppStream-8.6.0.Z.E4S:firefox-0:128.3.1-2.el8_6.aarch64 firefox-0:128.3.1-2.el8_6.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6) | fixed | firefox-0:128.3.1-2.el8_6.aarch64 | vendor fix → firefox-0:128.3.1-2.el8_6.aarch64 (RHSA-2024:8131) | csaf_redhat | |
| AppStream-8.6.0.Z.E4S:firefox-0:128.3.1-2.el8_6.ppc64le firefox-0:128.3.1-2.el8_6.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6) | fixed | firefox-0:128.3.1-2.el8_6.ppc64le | vendor fix → firefox-0:128.3.1-2.el8_6.ppc64le (RHSA-2024:8131) | csaf_redhat | |
| AppStream-8.6.0.Z.E4S:firefox-0:128.3.1-2.el8_6.s390x firefox-0:128.3.1-2.el8_6.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6) | fixed | firefox-0:128.3.1-2.el8_6.s390x | vendor fix → firefox-0:128.3.1-2.el8_6.s390x (RHSA-2024:8131) | csaf_redhat | |
| AppStream-8.6.0.Z.AUS:firefox-0:128.3.1-2.el8_6.src firefox-0:128.3.1-2.el8_6.src as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6) | fixed | firefox-0:128.3.1-2.el8_6.src | vendor fix → firefox-0:128.3.1-2.el8_6.src (RHSA-2024:8131) | csaf_redhat | |
| AppStream-8.6.0.Z.E4S:firefox-0:128.3.1-2.el8_6.src firefox-0:128.3.1-2.el8_6.src as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6) | fixed | firefox-0:128.3.1-2.el8_6.src | vendor fix → firefox-0:128.3.1-2.el8_6.src (RHSA-2024:8131) | csaf_redhat | |
| AppStream-8.6.0.Z.TUS:firefox-0:128.3.1-2.el8_6.src firefox-0:128.3.1-2.el8_6.src as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6) | fixed | firefox-0:128.3.1-2.el8_6.src | vendor fix → firefox-0:128.3.1-2.el8_6.src (RHSA-2024:8131) | csaf_redhat | |
| AppStream-8.6.0.Z.AUS:firefox-0:128.3.1-2.el8_6.x86_64 firefox-0:128.3.1-2.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6) | fixed | firefox-0:128.3.1-2.el8_6.x86_64 | vendor fix → firefox-0:128.3.1-2.el8_6.x86_64 (RHSA-2024:8131) | csaf_redhat | |
| AppStream-8.6.0.Z.E4S:firefox-0:128.3.1-2.el8_6.x86_64 firefox-0:128.3.1-2.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6) | fixed | firefox-0:128.3.1-2.el8_6.x86_64 | vendor fix → firefox-0:128.3.1-2.el8_6.x86_64 (RHSA-2024:8131) | csaf_redhat | |
| AppStream-8.6.0.Z.TUS:firefox-0:128.3.1-2.el8_6.x86_64 firefox-0:128.3.1-2.el8_6.x86_64 as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6) | fixed | firefox-0:128.3.1-2.el8_6.x86_64 | vendor fix → firefox-0:128.3.1-2.el8_6.x86_64 (RHSA-2024:8131) | csaf_redhat | |
| AppStream-8.8.0.Z.EUS:firefox-0:128.3.1-2.el8_8.aarch64 firefox-0:128.3.1-2.el8_8.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.8) | fixed | firefox-0:128.3.1-2.el8_8.aarch64 | vendor fix → firefox-0:128.3.1-2.el8_8.aarch64 (RHSA-2024:8033) | csaf_redhat | |
| AppStream-8.8.0.Z.EUS:firefox-0:128.3.1-2.el8_8.ppc64le firefox-0:128.3.1-2.el8_8.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.8.8) | fixed | firefox-0:128.3.1-2.el8_8.ppc64le | vendor fix → firefox-0:128.3.1-2.el8_8.ppc64le (RHSA-2024:8033) | csaf_redhat | |
| AppStream-8.8.0.Z.EUS:firefox-0:128.3.1-2.el8_8.s390x firefox-0:128.3.1-2.el8_8.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.8.8) | fixed | firefox-0:128.3.1-2.el8_8.s390x | vendor fix → firefox-0:128.3.1-2.el8_8.s390x (RHSA-2024:8033) | csaf_redhat | |
| AppStream-8.8.0.Z.EUS:firefox-0:128.3.1-2.el8_8.src firefox-0:128.3.1-2.el8_8.src as a component of Red Hat Enterprise Linux AppStream EUS (v.8.8) | fixed | firefox-0:128.3.1-2.el8_8.src | vendor fix → firefox-0:128.3.1-2.el8_8.src (RHSA-2024:8033) | csaf_redhat | |
| AppStream-8.8.0.Z.EUS:firefox-0:128.3.1-2.el8_8.x86_64 firefox-0:128.3.1-2.el8_8.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.8) | fixed | firefox-0:128.3.1-2.el8_8.x86_64 | vendor fix → firefox-0:128.3.1-2.el8_8.x86_64 (RHSA-2024:8033) | csaf_redhat | |
| AppStream-9.0.0.Z.E4S:firefox-0:128.3.1-2.el9_0.aarch64 firefox-0:128.3.1-2.el9_0.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.0) | fixed | firefox-0:128.3.1-2.el9_0.aarch64 | vendor fix → firefox-0:128.3.1-2.el9_0.aarch64 (RHSA-2024:8032) | csaf_redhat | |
| AppStream-9.0.0.Z.E4S:firefox-0:128.3.1-2.el9_0.ppc64le firefox-0:128.3.1-2.el9_0.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.0) | fixed | firefox-0:128.3.1-2.el9_0.ppc64le | vendor fix → firefox-0:128.3.1-2.el9_0.ppc64le (RHSA-2024:8032) | csaf_redhat | |
| AppStream-9.0.0.Z.E4S:firefox-0:128.3.1-2.el9_0.s390x firefox-0:128.3.1-2.el9_0.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.0) | fixed | firefox-0:128.3.1-2.el9_0.s390x | vendor fix → firefox-0:128.3.1-2.el9_0.s390x (RHSA-2024:8032) | csaf_redhat | |
| AppStream-9.0.0.Z.E4S:firefox-0:128.3.1-2.el9_0.src firefox-0:128.3.1-2.el9_0.src as a component of Red Hat Enterprise Linux AppStream E4S (v.9.0) | fixed | firefox-0:128.3.1-2.el9_0.src | vendor fix → firefox-0:128.3.1-2.el9_0.src (RHSA-2024:8032) | csaf_redhat | |
| AppStream-9.0.0.Z.E4S:firefox-0:128.3.1-2.el9_0.x86_64 firefox-0:128.3.1-2.el9_0.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.0) | fixed | firefox-0:128.3.1-2.el9_0.x86_64 | vendor fix → firefox-0:128.3.1-2.el9_0.x86_64 (RHSA-2024:8032) | csaf_redhat | |
| AppStream-9.2.0.Z.EUS:firefox-0:128.3.1-2.el9_2.aarch64 firefox-0:128.3.1-2.el9_2.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2) | fixed | firefox-0:128.3.1-2.el9_2.aarch64 | vendor fix → firefox-0:128.3.1-2.el9_2.aarch64 (RHSA-2024:8031) | csaf_redhat | |
| AppStream-9.2.0.Z.EUS:firefox-0:128.3.1-2.el9_2.ppc64le firefox-0:128.3.1-2.el9_2.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2) | fixed | firefox-0:128.3.1-2.el9_2.ppc64le | vendor fix → firefox-0:128.3.1-2.el9_2.ppc64le (RHSA-2024:8031) | csaf_redhat | |
| AppStream-9.2.0.Z.EUS:firefox-0:128.3.1-2.el9_2.s390x firefox-0:128.3.1-2.el9_2.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2) | fixed | firefox-0:128.3.1-2.el9_2.s390x | vendor fix → firefox-0:128.3.1-2.el9_2.s390x (RHSA-2024:8031) | csaf_redhat | |
| AppStream-9.2.0.Z.EUS:firefox-0:128.3.1-2.el9_2.src firefox-0:128.3.1-2.el9_2.src as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2) | fixed | firefox-0:128.3.1-2.el9_2.src | vendor fix → firefox-0:128.3.1-2.el9_2.src (RHSA-2024:8031) | csaf_redhat | |
| AppStream-9.2.0.Z.EUS:firefox-0:128.3.1-2.el9_2.x86_64 firefox-0:128.3.1-2.el9_2.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.2) | fixed | firefox-0:128.3.1-2.el9_2.x86_64 | vendor fix → firefox-0:128.3.1-2.el9_2.x86_64 (RHSA-2024:8031) | csaf_redhat | |
| AppStream-9.4.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el9_4.aarch64 firefox-0:128.3.1-2.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.3.1-2.el9_4.aarch64 | vendor fix → firefox-0:128.3.1-2.el9_4.aarch64 (RHSA-2024:7958) | csaf_redhat | |
| AppStream-9.4.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el9_4.ppc64le firefox-0:128.3.1-2.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.3.1-2.el9_4.ppc64le | vendor fix → firefox-0:128.3.1-2.el9_4.ppc64le (RHSA-2024:7958) | csaf_redhat | |
| AppStream-9.4.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el9_4.s390x firefox-0:128.3.1-2.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.3.1-2.el9_4.s390x | vendor fix → firefox-0:128.3.1-2.el9_4.s390x (RHSA-2024:7958) | csaf_redhat | |
| AppStream-9.4.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el9_4.src firefox-0:128.3.1-2.el9_4.src as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.3.1-2.el9_4.src | vendor fix → firefox-0:128.3.1-2.el9_4.src (RHSA-2024:7958) | csaf_redhat | |
| AppStream-9.4.0.Z.MAIN.EUS:firefox-0:128.3.1-2.el9_4.x86_64 firefox-0:128.3.1-2.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.3.1-2.el9_4.x86_64 | vendor fix → firefox-0:128.3.1-2.el9_4.x86_64 (RHSA-2024:7958) | csaf_redhat | |
| AppStream-9.5.0.Z.MAIN:firefox-0:128.4.0-1.el9_5.aarch64 firefox-0:128.4.0-1.el9_5.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.4.0-1.el9_5.aarch64 | vendor fix → firefox-0:128.4.0-1.el9_5.aarch64 (RHSA-2024:9554) | csaf_redhat | |
| AppStream-9.5.0.Z.MAIN:firefox-0:128.4.0-1.el9_5.ppc64le firefox-0:128.4.0-1.el9_5.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.4.0-1.el9_5.ppc64le | vendor fix → firefox-0:128.4.0-1.el9_5.ppc64le (RHSA-2024:9554) | csaf_redhat | |
| AppStream-9.5.0.Z.MAIN:firefox-0:128.4.0-1.el9_5.s390x firefox-0:128.4.0-1.el9_5.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.4.0-1.el9_5.s390x | vendor fix → firefox-0:128.4.0-1.el9_5.s390x (RHSA-2024:9554) | csaf_redhat | |
| AppStream-9.5.0.Z.MAIN:firefox-0:128.4.0-1.el9_5.src firefox-0:128.4.0-1.el9_5.src as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.4.0-1.el9_5.src | vendor fix → firefox-0:128.4.0-1.el9_5.src (RHSA-2024:9554) | csaf_redhat | |
| AppStream-9.5.0.Z.MAIN:firefox-0:128.4.0-1.el9_5.x86_64 firefox-0:128.4.0-1.el9_5.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | fixed | firefox-0:128.4.0-1.el9_5.x86_64 | vendor fix → firefox-0:128.4.0-1.el9_5.x86_64 (RHSA-2024:9554) | csaf_redhat | |
| 7Server-ELS:firefox-debuginfo-0:128.3.1-2.el7_9.s390x firefox-debuginfo-0:128.3.1-2.el7_9.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS) | fixed | firefox-debuginfo-0:128.3.1-2.el7_9.s390x | vendor fix → firefox-debuginfo-0:128.3.1-2.el7_9.s390x (RHSA-2024:8034) | csaf_redhat | |
| 7Server-ELS:firefox-debuginfo-0:128.3.1-2.el7_9.x86_64 firefox-debuginfo-0:128.3.1-2.el7_9.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS) | fixed | firefox-debuginfo-0:128.3.1-2.el7_9.x86_64 | vendor fix → firefox-debuginfo-0:128.3.1-2.el7_9.x86_64 (RHSA-2024:8034) | csaf_redhat | |
| AppStream-8.10.0.Z.MAIN.EUS:firefox-debuginfo-0:128.3.1-2.el8_10.aarch64 firefox-debuginfo-0:128.3.1-2.el8_10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8) | fixed | firefox-debuginfo-0:128.3.1-2.el8_10.aarch64 | vendor fix → firefox-debuginfo-0:128.3.1-2.el8_10.aarch64 (RHSA-2024:7977) | csaf_redhat |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.