VYPR

rpm package

opensuse/firefox-esr&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed

Vulnerabilities (2,366)

  • CVE-2026-16392CriJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16391HigJul 21, 2026
    affected < 140.13.0-1.1fixed 140.13.0-1.1

    Information disclosure in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16390CriJul 21, 2026
    affected < 140.13.0-1.1fixed 140.13.0-1.1

    Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16389CriJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Incorrect boundary conditions, integer overflow in the Libraries component in NSS. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16388CriJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16387CriJul 21, 2026
    affected < 140.13.0-1.1fixed 140.13.0-1.1

    Site isolation issue in the Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16386HigJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16385HigJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16384HigJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Information disclosure due to uninitialized memory in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16383CriJul 21, 2026
    affected < 140.13.0-1.1fixed 140.13.0-1.1

    Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16382CriJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16381CriJul 21, 2026
    affected < 140.13.0-1.1fixed 140.13.0-1.1

    Same-origin policy bypass in the Networking: DNS component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16380CriJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16379HigJul 21, 2026
    affected < 140.13.0-1.1fixed 140.13.0-1.1

    Privilege escalation in the DOM: Content Processes component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16378HigJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16377CriJul 21, 2026
    affected < 140.13.0-1.1fixed 140.13.0-1.1

    Mitigation bypass in the PDF Viewer component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16376HigJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Denial-of-service in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

  • CVE-2026-16375CriJul 21, 2026
    affected < 140.13.0-1.1fixed 140.13.0-1.1

    Site isolation issue in the Networking: HTTP component. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16374HigJul 21, 2026
    affected < 140.13.0-1.1fixed 140.13.0-1.1

    Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

  • CVE-2026-16373HigJul 21, 2026
    affected < 153.0-1.1fixed 153.0-1.1

    Information disclosure in the Privacy component in Firefox for Android. This vulnerability was fixed in Firefox 153.

Page 2 of 119