VYPR

rpm package

suse/MozillaFirefox&distro=SUSE Linux Enterprise Module for Desktop Applications 15 SP4

pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4

Vulnerabilities (206)

  • CVE-2022-29914MedDec 22, 2022
    affected < 91.9.0-150200.152.33.1fixed 91.9.0-150200.152.33.1

    When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29912MedDec 22, 2022
    affected < 91.9.0-150200.152.33.1fixed 91.9.0-150200.152.33.1

    Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29911MedDec 22, 2022
    affected < 91.9.0-150200.152.33.1fixed 91.9.0-150200.152.33.1

    An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation could lead to script execution without allow-scripts being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

  • CVE-2022-29909HigDec 22, 2022
    affected < 91.9.0-150200.152.33.1fixed 91.9.0-150200.152.33.1

    Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Fir

  • CVE-2022-1802HigDec 22, 2022
    affected < 91.9.1-150200.152.40.1fixed 91.9.1-150200.152.40.1

    If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox

  • CVE-2022-1529HigDec 22, 2022
    affected < 91.9.1-150200.152.40.1fixed 91.9.1-150200.152.40.1

    An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects F

Page 11 of 11