rpm package
opensuse/MozillaFirefox&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,633)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-74980 | Med | 6.5 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | |
| CVE-2026-74979 | Cri | 9.8 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74978 | Hig | 8.1 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74977 | Hig | 7.5 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74976 | Med | 6.5 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74975 | Med | 5.4 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154. | |
| CVE-2026-74974 | Med | 5.4 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74973 | Med | 4.2 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74972 | Med | 4.3 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74971 | Med | 4.3 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74970 | Med | 5.4 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74969 | Hig | 8.8 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74968 | Med | 5.4 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74967 | Med | 5.4 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74966 | Hig | 7.5 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74965 | Hig | 8.8 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74964 | Cri | 9.8 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74963 | Med | 5.4 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74962 | Hig | 8.1 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74961 | Cri | 9.1 | < 154.0-1.1 | 154.0-1.1 | Aug 18, 2026 | Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
- affected < 154.0-1.1fixed 154.0-1.1
Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
- affected < 154.0-1.1fixed 154.0-1.1
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.
- affected < 154.0-1.1fixed 154.0-1.1
Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 154.0-1.1fixed 154.0-1.1
Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Page 3 of 132