rpm package
opensuse/firefox-esr&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,418)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-9792 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Apr 26, 2019 | The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability a | |
| CVE-2019-9791 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Apr 26, 2019 | The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for | |
| CVE-2019-9790 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Apr 26, 2019 | A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60 | |
| CVE-2019-9789 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Apr 26, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firef | |
| CVE-2019-9788 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Apr 26, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrar | |
| CVE-2018-18511 | Med | 4.3 | < 128.5.1-1.1 | 128.5.1-1.1 | Apr 26, 2019 | Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1. | |
| CVE-2018-18498 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, an | |
| CVE-2018-18497 | Med | 6.5 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: l | |
| CVE-2018-18496 | Hig | 8.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Win | |
| CVE-2018-18495 | Med | 6.5 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted | |
| CVE-2018-18494 | Med | 6.5 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerabili | |
| CVE-2018-18493 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, F | |
| CVE-2018-18492 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 6 | |
| CVE-2018-12407 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64. | |
| CVE-2018-12406 | Hig | 8.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firef | |
| CVE-2018-12405 | Cri | 9.8 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner | |
| CVE-2018-12403 | Med | 5.3 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63. | |
| CVE-2018-12402 | Med | 6.5 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by i | |
| CVE-2018-12401 | Hig | 7.5 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63. | |
| CVE-2018-12400 | Med | 5.3 | < 128.5.1-1.1 | 128.5.1-1.1 | Feb 28, 2019 | In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions |
- affected < 128.5.1-1.1fixed 128.5.1-1.1
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability a
- affected < 128.5.1-1.1fixed 128.5.1-1.1
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for
- affected < 128.5.1-1.1fixed 128.5.1-1.1
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60
- affected < 128.5.1-1.1fixed 128.5.1-1.1
Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firef
- affected < 128.5.1-1.1fixed 128.5.1-1.1
Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrar
- affected < 128.5.1-1.1fixed 128.5.1-1.1
Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
- affected < 128.5.1-1.1fixed 128.5.1-1.1
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, an
- affected < 128.5.1-1.1fixed 128.5.1-1.1
Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: l
- affected < 128.5.1-1.1fixed 128.5.1-1.1
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Win
- affected < 128.5.1-1.1fixed 128.5.1-1.1
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted
- affected < 128.5.1-1.1fixed 128.5.1-1.1
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerabili
- affected < 128.5.1-1.1fixed 128.5.1-1.1
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, F
- affected < 128.5.1-1.1fixed 128.5.1-1.1
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 6
- affected < 128.5.1-1.1fixed 128.5.1-1.1
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64.
- affected < 128.5.1-1.1fixed 128.5.1-1.1
Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firef
- affected < 128.5.1-1.1fixed 128.5.1-1.1
Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner
- affected < 128.5.1-1.1fixed 128.5.1-1.1
If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63.
- affected < 128.5.1-1.1fixed 128.5.1-1.1
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by i
- affected < 128.5.1-1.1fixed 128.5.1-1.1
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.
- affected < 128.5.1-1.1fixed 128.5.1-1.1
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions
Page 70 of 121