rpm package
opensuse/firefox-esr&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweed
Vulnerabilities (2,567)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-84124 | Med | 5.4 | < 153.2.0-1.1 | 153.2.0-1.1 | Sep 1, 2026 | Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| CVE-2026-84123 | Hig | 8.8 | < 153.2.0-1.1 | 153.2.0-1.1 | Sep 1, 2026 | Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |
| CVE-2026-84122 | Med | 5.4 | < 153.2.0-1.1 | 153.2.0-1.1 | Sep 1, 2026 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| CVE-2026-84121 | Cri | 9.6 | < 153.2.0-1.1 | 153.2.0-1.1 | Sep 1, 2026 | Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| CVE-2026-84120 | Med | 5.4 | < 153.2.0-1.1 | 153.2.0-1.1 | Sep 1, 2026 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| CVE-2026-84119 | Cri | 9.6 | < 153.2.0-1.1 | 153.2.0-1.1 | Sep 1, 2026 | Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. | |
| CVE-2026-84118 | Med | 5.4 | < 153.2.0-1.1 | 153.2.0-1.1 | Sep 1, 2026 | Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. | |
| CVE-2026-75874 | Cri | 10.0 | < 153.2.0-1.1 | 153.2.0-1.1 | Aug 18, 2026 | Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. | |
| CVE-2026-74990 | Cri | 9.8 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vul | |
| CVE-2026-74988 | Cri | 9.8 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in | |
| CVE-2026-74987 | Cri | 9.8 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vul | |
| CVE-2026-74986 | Cri | 9.1 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74985 | Cri | 9.8 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74984 | Med | 6.8 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74983 | Hig | 8.1 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. | |
| CVE-2026-74982 | Hig | 7.5 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74981 | Hig | 8.1 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74979 | Cri | 9.8 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74978 | Hig | 8.1 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. | |
| CVE-2026-74977 | Hig | 7.5 | < 153.1.0-1.1 | 153.1.0-1.1 | Aug 18, 2026 | Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1. |
- affected < 153.2.0-1.1fixed 153.2.0-1.1
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- affected < 153.2.0-1.1fixed 153.2.0-1.1
Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- affected < 153.2.0-1.1fixed 153.2.0-1.1
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- affected < 153.2.0-1.1fixed 153.2.0-1.1
Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- affected < 153.2.0-1.1fixed 153.2.0-1.1
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- affected < 153.2.0-1.1fixed 153.2.0-1.1
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- affected < 153.2.0-1.1fixed 153.2.0-1.1
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- affected < 153.2.0-1.1fixed 153.2.0-1.1
Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vul
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vul
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
- affected < 153.1.0-1.1fixed 153.1.0-1.1
Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Page 8 of 129