rpm package
suse/MozillaFirefox&distro=SUSE Linux Enterprise Desktop 12 SP3
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Vulnerabilities (129)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-7791 | — | < 52.3.0esr-109.3.1 | 52.3.0esr-109.3.1 | Jun 11, 2018 | On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR | ||
| CVE-2017-7787 | — | < 52.3.0esr-109.3.1 | 52.3.0esr-109.3.1 | Jun 11, 2018 | Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | ||
| CVE-2017-7786 | — | < 52.3.0esr-109.3.1 | 52.3.0esr-109.3.1 | Jun 11, 2018 | A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | ||
| CVE-2017-7785 | — | < 52.3.0esr-109.3.1 | 52.3.0esr-109.3.1 | Jun 11, 2018 | A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | ||
| CVE-2017-7784 | — | < 52.3.0esr-109.3.1 | 52.3.0esr-109.3.1 | Jun 11, 2018 | A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | ||
| CVE-2017-7782 | — | < 52.3.0esr-109.3.1 | 52.3.0esr-109.3.1 | Jun 11, 2018 | An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunde | ||
| CVE-2017-7779 | — | < 52.3.0esr-109.3.1 | 52.3.0esr-109.3.1 | Jun 11, 2018 | Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbi | ||
| CVE-2017-7753 | — | < 52.3.0esr-109.3.1 | 52.3.0esr-109.3.1 | Jun 11, 2018 | An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | ||
| CVE-2017-16541 | Med | 6.5 | < 60.2.2esr-109.46.1 | 60.2.2esr-109.46.1 | Nov 4, 2017 | Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected. |
- CVE-2017-7791Jun 11, 2018affected < 52.3.0esr-109.3.1fixed 52.3.0esr-109.3.1
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR
- CVE-2017-7787Jun 11, 2018affected < 52.3.0esr-109.3.1fixed 52.3.0esr-109.3.1
Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
- CVE-2017-7786Jun 11, 2018affected < 52.3.0esr-109.3.1fixed 52.3.0esr-109.3.1
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
- CVE-2017-7785Jun 11, 2018affected < 52.3.0esr-109.3.1fixed 52.3.0esr-109.3.1
A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
- CVE-2017-7784Jun 11, 2018affected < 52.3.0esr-109.3.1fixed 52.3.0esr-109.3.1
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
- CVE-2017-7782Jun 11, 2018affected < 52.3.0esr-109.3.1fixed 52.3.0esr-109.3.1
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunde
- CVE-2017-7779Jun 11, 2018affected < 52.3.0esr-109.3.1fixed 52.3.0esr-109.3.1
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbi
- CVE-2017-7753Jun 11, 2018affected < 52.3.0esr-109.3.1fixed 52.3.0esr-109.3.1
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
- affected < 60.2.2esr-109.46.1fixed 60.2.2esr-109.46.1
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
Page 7 of 7