rpm package
opensuse/MozillaFirefox&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,706)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-92079 | Cri | 9.1 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92078 | Med | 6.5 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92077 | Med | 6.5 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92076 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92075 | Cri | 9.1 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92074 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92073 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92072 | Hig | 8.0 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92071 | Cri | 9.6 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92070 | Med | 4.3 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92069 | Med | 5.4 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92068 | Med | 5.4 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92067 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92066 | Cri | 9.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |
| CVE-2026-92065 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92064 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92063 | Med | 6.5 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |
| CVE-2026-92062 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. | |
| CVE-2026-92061 | Cri | 9.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. | |
| CVE-2026-92060 | Hig | 8.8 | < 156.0-1.1 | 156.0-1.1 | Sep 15, 2026 | Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3. |
- affected < 156.0-1.1fixed 156.0-1.1
Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- affected < 156.0-1.1fixed 156.0-1.1
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- affected < 156.0-1.1fixed 156.0-1.1
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
- affected < 156.0-1.1fixed 156.0-1.1
Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.
- affected < 156.0-1.1fixed 156.0-1.1
Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Page 1 of 136