rpm package
opensuse/MozillaThunderbird&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweed
Vulnerabilities (1,666)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-12392 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Feb 28, 2019 | When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3. | |
| CVE-2018-12391 | Hig | 8.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Feb 28, 2019 | During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access | |
| CVE-2018-12390 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner | |
| CVE-2018-12389 | Hig | 8.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects | |
| CVE-2018-18505 | Cri | 10.0 | < 91.1.1-1.1 | 91.1.1-1.1 | Feb 5, 2019 | An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is star | |
| CVE-2018-18501 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Feb 5, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner | |
| CVE-2018-18500 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Feb 5, 2019 | A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox | |
| CVE-2019-7317 | Med | 5.3 | < 91.1.1-1.1 | 91.1.1-1.1 | Feb 4, 2019 | png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. | |
| CVE-2018-18356 | Hig | 8.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Dec 11, 2018 | An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2018-18335 | Hig | 8.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Dec 11, 2018 | Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2018-17466 | Hig | 8.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Nov 14, 2018 | Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | |
| CVE-2018-5188 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Oct 18, 2018 | Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, | |
| CVE-2018-5187 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Oct 18, 2018 | Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1 | |
| CVE-2018-5156 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Oct 18, 2018 | A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR | |
| CVE-2018-12385 | Hig | 7.0 | < 91.1.1-1.1 | 91.1.1-1.1 | Oct 18, 2018 | A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache | |
| CVE-2018-12383 | Med | 5.5 | < 91.1.1-1.1 | 91.1.1-1.1 | Oct 18, 2018 | If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new ma | |
| CVE-2018-12378 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Oct 18, 2018 | A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thund | |
| CVE-2018-12377 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Oct 18, 2018 | A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and | |
| CVE-2018-12376 | Cri | 9.8 | < 91.1.1-1.1 | 91.1.1-1.1 | Oct 18, 2018 | Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, | |
| CVE-2018-12374 | Med | 4.3 | < 91.1.1-1.1 | 91.1.1-1.1 | Oct 18, 2018 | Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9. |
- affected < 91.1.1-1.1fixed 91.1.1-1.1
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
- affected < 91.1.1-1.1fixed 91.1.1-1.1
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access
- affected < 91.1.1-1.1fixed 91.1.1-1.1
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner
- affected < 91.1.1-1.1fixed 91.1.1-1.1
Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects
- affected < 91.1.1-1.1fixed 91.1.1-1.1
An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is star
- affected < 91.1.1-1.1fixed 91.1.1-1.1
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner
- affected < 91.1.1-1.1fixed 91.1.1-1.1
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox
- affected < 91.1.1-1.1fixed 91.1.1-1.1
png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
- affected < 91.1.1-1.1fixed 91.1.1-1.1
An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 91.1.1-1.1fixed 91.1.1-1.1
Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- affected < 91.1.1-1.1fixed 91.1.1-1.1
Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
- affected < 91.1.1-1.1fixed 91.1.1-1.1
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60,
- affected < 91.1.1-1.1fixed 91.1.1-1.1
Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1
- affected < 91.1.1-1.1fixed 91.1.1-1.1
A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR
- affected < 91.1.1-1.1fixed 91.1.1-1.1
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache
- affected < 91.1.1-1.1fixed 91.1.1-1.1
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new ma
- affected < 91.1.1-1.1fixed 91.1.1-1.1
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thund
- affected < 91.1.1-1.1fixed 91.1.1-1.1
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and
- affected < 91.1.1-1.1fixed 91.1.1-1.1
Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2,
- affected < 91.1.1-1.1fixed 91.1.1-1.1
Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9.
Page 46 of 84