rpm package
almalinux/firefox-x11
pkg:rpm/almalinux/firefox-x11
Vulnerabilities (478)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-12314 | Hig | 7.5 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12313 | Med | 4.7 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12312 | Hig | 7.5 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12311 | Med | 4.7 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12310 | Hig | 7.5 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12309 | Med | 6.5 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12308 | Med | 5.3 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12307 | Med | 5.3 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12306 | Med | 5.3 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12305 | Hig | 7.5 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12304 | Cri | 9.1 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12302 | Med | 6.5 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12299 | Med | 5.4 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12298 | Med | 5.4 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12297 | Cri | 9.6 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12296 | Cri | 9.6 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12295 | Cri | 9.6 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12294 | Cri | 9.6 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12292 | Hig | 8.1 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12. | |
| CVE-2026-12291 | Hig | 8.8 | < 140.12.0-1.el9_8.alma.1 | 140.12.0-1.el9_8.alma.1 | Jun 16, 2026 | Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12. |
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
- affected < 140.12.0-1.el9_8.alma.1fixed 140.12.0-1.el9_8.alma.1
Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
Page 3 of 24