bug_32618 (https://gitweb.torproject.org/user/gk/tor-browser.git/log/?h=bug_32618) has the backports. I did not build the changes yet but I looked at possible parseFromString() calls that might still be problematic AND on esr68 while not being present anymore when the patches landed on Mozilla's branches. We are good here, though.
I also double-checked that the patches for those two bugs are the only ones we need to backport:
Bug 1585769 is relevant here but the picture-in-picture video feature is only enabled in Windows nightlies if the code is esr68, so I think we can avoid backporting that fix.
Bug 1585588 is not affecting us as we don't ship that extension and it should be fixed by bug 1590526 anyway (which fixed bug 1576508 as well).
Trac: Status: new to needs_review Keywords: TorBrowserTeam201911 deleted, TorBrowserTeam201911R added Actualpoints: N/Ato 0.2