In general, vulnerabilities are those bugs that can actually be exploited to perform malicious tasks. Most crashes are not security vulnerabilities. Although important to fix, they don't inherently cause a problem for the browser's security.
What should be considered vulnerabilities or security hazards by default:
Generally not security vulnerabilities:
If you find an issue in UXP or the applications it builds on that could impact the security or safety of users please do not make an issue on Gitea about it. Gitea does not support restricted viewability for security sensitive bugs.
If you want to report a security-sensitive issue then please go to the forum and report the issue via a private message to Moonchild (the founder and prime responsible for security issues). The forum's private message system is fully secure since your visits are encrypted and private messages are not available to anyone except the recipient (not even moderators!).
You will be informed via private message if the vulnerability report is accepted or declined, with reasoning. Security updates occur regularly and are given priority over most other development tasks. In general, they can be solved relatively quickly and will be included in the next point release (third digit if not rolled into a more major one).