VYPR

rpm package

opensuse/mozilla-nss&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/mozilla-nss&distro=openSUSE%20Leap%2016.0

Vulnerabilities (115)

  • CVE-2026-74967MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74966HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Information disclosure in the Form Autofill component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74965HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74964CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74963MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74962HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Site isolation issue in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74961CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74960HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74959CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74958HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Information disclosure in the WebRTC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74957HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Mitigation bypass in the Safe Browsing component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74956CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74955HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74954HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Information disclosure due to side-channel in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74953HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74950HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74949HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74948MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74947HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74946HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Page 2 of 6