rpm package
opensuse/firefox-esr&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,567)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-100781 | Cri | 9.6 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100780 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100779 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100778 | Cri | 9.6 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100777 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100776 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| CVE-2026-100775 | Cri | 9.6 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Sandbox escape in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100774 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100773 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100772 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| CVE-2026-100771 | Hig | 8.1 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Undefined behavior in the DOM: Streams component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100770 | Cri | 9.6 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100769 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17. | |
| CVE-2026-100767 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100766 | Med | 4.3 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100765 | Hig | 8.8 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| CVE-2026-100762 | Cri | 9.6 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100760 | Cri | 9.6 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157. | |
| CVE-2026-100759 | Hig | 8.1 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. | |
| CVE-2026-100758 | Cri | 9.6 | < 153.4.0-1.1 | 153.4.0-1.1 | Sep 29, 2026 | Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. |
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Sandbox escape in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Undefined behavior in the DOM: Streams component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the Networking: Cache component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
- affected < 153.4.0-1.1fixed 153.4.0-1.1
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Page 3 of 129