rpm package
almalinux/firefox
pkg:rpm/almalinux/firefox
Vulnerabilities (590)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-22741 | Hig | 7.5 | < 91.5.0-1.el8_5.alma | 91.5.0-1.el8_5.alma | Dec 22, 2022 | When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. | |
| CVE-2022-22740 | Hig | 8.8 | < 91.5.0-1.el8_5.alma | 91.5.0-1.el8_5.alma | Dec 22, 2022 | Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. | |
| CVE-2022-22739 | Med | 6.5 | < 91.5.0-1.el8_5.alma | 91.5.0-1.el8_5.alma | Dec 22, 2022 | Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. | |
| CVE-2022-22738 | Hig | 8.8 | < 91.5.0-1.el8_5.alma | 91.5.0-1.el8_5.alma | Dec 22, 2022 | Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. | |
| CVE-2022-22737 | Hig | 7.5 | < 91.5.0-1.el8_5.alma | 91.5.0-1.el8_5.alma | Dec 22, 2022 | Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. | |
| CVE-2022-1802 | Hig | 8.8 | < 91.9.1-1.el8_6.alma | 91.9.1-1.el8_6.alma | Dec 22, 2022 | If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox | |
| CVE-2022-1529 | Hig | 8.8 | < 91.9.1-1.el8_6.alma | 91.9.1-1.el8_6.alma | Dec 22, 2022 | An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects F | |
| CVE-2022-1196 | Med | 6.5 | < 91.8.0-1.el8_5.alma | 91.8.0-1.el8_5.alma | Dec 22, 2022 | After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8. | |
| CVE-2022-1097 | Med | 6.5 | < 91.8.0-1.el8_5.alma | 91.8.0-1.el8_5.alma | Dec 22, 2022 | NSSToken objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8. | |
| CVE-2021-4140 | Cri | 10.0 | < 91.5.0-1.el8_5.alma | 91.5.0-1.el8_5.alma | Dec 22, 2022 | It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. | |
| CVE-2022-40674 | Hig | 8.1 | < 102.3.0-7.el9_0.alma | 102.3.0-7.el9_0.alma | Sep 14, 2022 | libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. | |
| CVE-2022-24713 | Hig | 7.5 | < 91.8.0-1.el8_5.alma | 91.8.0-1.el8_5.alma | Mar 8, 2022 | regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane | |
| CVE-2022-25315 | Cri | 9.8 | < 91.7.0-3.el8_5.alma | 91.7.0-3.el8_5.alma | Feb 18, 2022 | In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. | |
| CVE-2022-25236 | Cri | 9.8 | < 91.7.0-3.el8_5.alma | 91.7.0-3.el8_5.alma | Feb 16, 2022 | xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs. | |
| CVE-2022-25235 | Cri | 9.8 | < 91.7.0-3.el8_5.alma | 91.7.0-3.el8_5.alma | Feb 16, 2022 | xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. | |
| CVE-2021-43546 | Med | 4.3 | < 91.4.0-1.el8_5.alma | 91.4.0-1.el8_5.alma | Dec 8, 2021 | It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | |
| CVE-2021-43545 | Med | 6.5 | < 91.4.0-1.el8_5.alma | 91.4.0-1.el8_5.alma | Dec 8, 2021 | Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | |
| CVE-2021-43543 | Med | 6.1 | < 91.4.0-1.el8_5.alma | 91.4.0-1.el8_5.alma | Dec 8, 2021 | Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | |
| CVE-2021-43542 | Med | 6.5 | < 91.4.0-1.el8_5.alma | 91.4.0-1.el8_5.alma | Dec 8, 2021 | Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | |
| CVE-2021-43541 | Med | 6.5 | < 91.4.0-1.el8_5.alma | 91.4.0-1.el8_5.alma | Dec 8, 2021 | When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. |
- affected < 91.5.0-1.el8_5.almafixed 91.5.0-1.el8_5.alma
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
- affected < 91.5.0-1.el8_5.almafixed 91.5.0-1.el8_5.alma
Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
- affected < 91.5.0-1.el8_5.almafixed 91.5.0-1.el8_5.alma
Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
- affected < 91.5.0-1.el8_5.almafixed 91.5.0-1.el8_5.alma
Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
- affected < 91.5.0-1.el8_5.almafixed 91.5.0-1.el8_5.alma
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
- affected < 91.9.1-1.el8_6.almafixed 91.9.1-1.el8_6.alma
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox
- affected < 91.9.1-1.el8_6.almafixed 91.9.1-1.el8_6.alma
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects F
- affected < 91.8.0-1.el8_5.almafixed 91.8.0-1.el8_5.alma
After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8.
- affected < 91.8.0-1.el8_5.almafixed 91.8.0-1.el8_5.alma
NSSToken objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
- affected < 91.5.0-1.el8_5.almafixed 91.5.0-1.el8_5.alma
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
- affected < 102.3.0-7.el9_0.almafixed 102.3.0-7.el9_0.alma
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
- affected < 91.8.0-1.el8_5.almafixed 91.8.0-1.el8_5.alma
regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane
- affected < 91.7.0-3.el8_5.almafixed 91.7.0-3.el8_5.alma
In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
- affected < 91.7.0-3.el8_5.almafixed 91.7.0-3.el8_5.alma
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.
- affected < 91.7.0-3.el8_5.almafixed 91.7.0-3.el8_5.alma
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
- affected < 91.4.0-1.el8_5.almafixed 91.4.0-1.el8_5.alma
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- affected < 91.4.0-1.el8_5.almafixed 91.4.0-1.el8_5.alma
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- affected < 91.4.0-1.el8_5.almafixed 91.4.0-1.el8_5.alma
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- affected < 91.4.0-1.el8_5.almafixed 91.4.0-1.el8_5.alma
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- affected < 91.4.0-1.el8_5.almafixed 91.4.0-1.el8_5.alma
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Page 29 of 30