VYPR

rpm package

suse/MozillaFirefox&distro=SUSE Enterprise Storage 6

pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Enterprise%20Storage%206

Vulnerabilities (183)

  • CVE-2021-23969MedFeb 26, 2021
    affected < 78.8.0-3.133.1fixed 78.8.0-3.133.1

    As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintent

  • CVE-2021-23968MedFeb 26, 2021
    affected < 78.8.0-3.133.1fixed 78.8.0-3.133.1

    If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affe

  • CVE-2020-26976MedJan 7, 2021
    affected < 78.7.0-3.128.2fixed 78.7.0-3.128.2

    When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affe

Page 10 of 10