rpm package
opensuse/MozillaFirefox&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,706)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-92059 | Cri | 9.3 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92058 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92057 | Cri | 9.1 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92056 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92055 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92054 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92053 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92052 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92051 | Cri | 9.1 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |
| CVE-2026-92050 | Cri | 9.1 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |
| CVE-2026-92049 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92048 | Cri | 9.0 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92047 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92046 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92045 | Cri | 9.6 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92044 | Hig | 7.5 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92043 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92042 | Hig | 7.5 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92041 | Cri | 9.1 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92040 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
- affected < 156.0-1.1fixed 156.0-1.1
Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- affected < 156.0-1.1fixed 156.0-1.1
Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- affected < 156.0-1.1fixed 156.0-1.1
Use-after-free in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Race condition in the DOM: Content Processes component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
Page 2 of 136