VYPR

rpm package

opensuse/MozillaThunderbird&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweed

Vulnerabilities (1,666)

  • CVE-2022-2226MedDec 22, 2022
    affected < 91.11.0-1.1fixed 91.11.0-1.1

    An OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a digital signature, the email's date will be shown. If the dates were different, then Thunderbird didn't report the email as having an invalid

  • CVE-2022-2200HigDec 22, 2022
    affected < 91.11.0-1.1fixed 91.11.0-1.1

    If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

  • CVE-2022-29917CriDec 22, 2022
    affected < 91.9.0-1.1fixed 91.9.0-1.1

    Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could

  • CVE-2022-29916MedDec 22, 2022
    affected < 91.9.0-1.1fixed 91.9.0-1.1

    Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29914MedDec 22, 2022
    affected < 91.9.0-1.1fixed 91.9.0-1.1

    When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29913MedDec 22, 2022
    affected < 91.9.0-1.1fixed 91.9.0-1.1

    The parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child process. This vulnerability affects Thunderbird < 91.9.

  • CVE-2022-29912MedDec 22, 2022
    affected < 91.9.0-1.1fixed 91.9.0-1.1

    Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29911MedDec 22, 2022
    affected < 91.9.0-1.1fixed 91.9.0-1.1

    An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation could lead to script execution without allow-scripts being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29909HigDec 22, 2022
    affected < 91.9.0-1.1fixed 91.9.0-1.1

    Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Fir

  • CVE-2022-26486CriKEVDec 22, 2022
    affected < 91.7.0-1.1fixed 91.7.0-1.1

    An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderb

  • CVE-2022-26485HigKEVDec 22, 2022
    affected < 91.7.0-1.1fixed 91.7.0-1.1

    Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and

  • CVE-2022-26387HigDec 22, 2022
    affected < 91.7.0-1.1fixed 91.7.0-1.1

    When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7,

  • CVE-2022-26386MedDec 22, 2022
    affected < 91.7.0-1.1fixed 91.7.0-1.1

    Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in /tmp, but this behavior was changed to download them to /tmp where they could be affected by other local users. This behavior was reverted to the origin

  • CVE-2022-26384CriDec 22, 2022
    affected < 91.7.0-1.1fixed 91.7.0-1.1

    If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefo

  • CVE-2022-26383MedDec 22, 2022
    affected < 91.7.0-1.1fixed 91.7.0-1.1

    When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

  • CVE-2022-26381HigDec 22, 2022
    affected < 91.7.0-1.1fixed 91.7.0-1.1

    An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

  • CVE-2022-22764HigDec 22, 2022
    affected < 91.6.0-1.1fixed 91.6.0-1.1

    Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitr

  • CVE-2022-22763HigDec 22, 2022
    affected < 91.6.0-1.1fixed 91.6.0-1.1

    When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.

  • CVE-2022-22761HigDec 22, 2022
    affected < 91.6.0-1.1fixed 91.6.0-1.1

    Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

  • CVE-2022-22760MedDec 22, 2022
    affected < 91.6.0-1.1fixed 91.6.0-1.1

    When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thun

Page 33 of 84