VYPR

rpm package

opensuse/mozilla-nss&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/mozilla-nss&distro=openSUSE%20Leap%2016.0

Vulnerabilities (115)

  • CVE-2026-74990CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vul

  • CVE-2026-74988CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in

  • CVE-2026-74987CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vul

  • CVE-2026-74986CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74985CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74984MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74983HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Mitigation bypass in the Data Loss Prevention component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74982HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Denial-of-service in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74981HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74979CriAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74978HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Clickjacking issue in the Widget component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74977HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74976MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74974MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74973MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Race condition, use-after-free in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74972MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Information disclosure in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74971MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Information disclosure in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74970MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74969HigAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74968MedAug 18, 2026
    affected < 3.125-160000.1.1fixed 3.125-160000.1.1

    Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Page 1 of 6