VYPR

rpm package

opensuse/firefox-esr&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed

Vulnerabilities (2,418)

  • CVE-2019-9792CriApr 26, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability a

  • CVE-2019-9791CriApr 26, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for

  • CVE-2019-9790CriApr 26, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60

  • CVE-2019-9789CriApr 26, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firef

  • CVE-2019-9788CriApr 26, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrar

  • CVE-2018-18511MedApr 26, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

  • CVE-2018-18498CriFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, an

  • CVE-2018-18497MedFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: l

  • CVE-2018-18496HigFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Win

  • CVE-2018-18495MedFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted

  • CVE-2018-18494MedFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerabili

  • CVE-2018-18493CriFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, F

  • CVE-2018-18492CriFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 6

  • CVE-2018-12407CriFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64.

  • CVE-2018-12406HigFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firef

  • CVE-2018-12405CriFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner

  • CVE-2018-12403MedFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63.

  • CVE-2018-12402MedFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by i

  • CVE-2018-12401HigFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.

  • CVE-2018-12400MedFeb 28, 2019
    affected < 128.5.1-1.1fixed 128.5.1-1.1

    In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions

Page 70 of 121