rpm package
suse/MozillaFirefox&distro=SUSE Linux Enterprise Module for Desktop Applications 15 SP4
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP4
Vulnerabilities (206)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-29914 | Med | 6.5 | < 91.9.0-150200.152.33.1 | 91.9.0-150200.152.33.1 | Dec 22, 2022 | When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. | |
| CVE-2022-29912 | Med | 6.1 | < 91.9.0-150200.152.33.1 | 91.9.0-150200.152.33.1 | Dec 22, 2022 | Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. | |
| CVE-2022-29911 | Med | 6.1 | < 91.9.0-150200.152.33.1 | 91.9.0-150200.152.33.1 | Dec 22, 2022 | An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation could lead to script execution without allow-scripts being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. | |
| CVE-2022-29909 | Hig | 8.8 | < 91.9.0-150200.152.33.1 | 91.9.0-150200.152.33.1 | Dec 22, 2022 | Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Fir | |
| CVE-2022-1802 | Hig | 8.8 | < 91.9.1-150200.152.40.1 | 91.9.1-150200.152.40.1 | Dec 22, 2022 | If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox | |
| CVE-2022-1529 | Hig | 8.8 | < 91.9.1-150200.152.40.1 | 91.9.1-150200.152.40.1 | Dec 22, 2022 | An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects F |
- affected < 91.9.0-150200.152.33.1fixed 91.9.0-150200.152.33.1
When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- affected < 91.9.0-150200.152.33.1fixed 91.9.0-150200.152.33.1
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- affected < 91.9.0-150200.152.33.1fixed 91.9.0-150200.152.33.1
An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation could lead to script execution without allow-scripts being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
- affected < 91.9.0-150200.152.33.1fixed 91.9.0-150200.152.33.1
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Fir
- affected < 91.9.1-150200.152.40.1fixed 91.9.1-150200.152.40.1
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox
- affected < 91.9.1-150200.152.40.1fixed 91.9.1-150200.152.40.1
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects F
Page 11 of 11