rpm package
suse/MozillaFirefox&distro=SUSE Linux Enterprise Server 11 SP3-TERADATA
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP3-TERADATA
Vulnerabilities (300)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2018-5157 | — | < 52.8.0esr-72.32.1 | 52.8.0esr-72.32.1 | Jun 11, 2018 | Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Fi | ||
| CVE-2018-5155 | — | < 52.8.0esr-72.32.1 | 52.8.0esr-72.32.1 | Jun 11, 2018 | A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8. | ||
| CVE-2018-5154 | — | < 52.8.0esr-72.32.1 | 52.8.0esr-72.32.1 | Jun 11, 2018 | A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8. | ||
| CVE-2018-5150 | — | < 52.8.0esr-72.32.1 | 52.8.0esr-72.32.1 | Jun 11, 2018 | Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbi | ||
| CVE-2018-5148 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2. | ||
| CVE-2018-5147 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1. | ||
| CVE-2018-5146 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7. | ||
| CVE-2018-5145 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7. | ||
| CVE-2018-5144 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7. | ||
| CVE-2018-5131 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a web | ||
| CVE-2018-5130 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59. | ||
| CVE-2018-5129 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52 | ||
| CVE-2018-5127 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59. | ||
| CVE-2018-5125 | — | < 52.7.3esr-72.27.2 | 52.7.3esr-72.27.2 | Jun 11, 2018 | Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox | ||
| CVE-2018-5117 | — | < 52.6.0esr-72.20.2 | 52.6.0esr-72.20.2 | Jun 11, 2018 | If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are o | ||
| CVE-2018-5104 | — | < 52.6.0esr-72.20.2 | 52.6.0esr-72.20.2 | Jun 11, 2018 | A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. | ||
| CVE-2018-5103 | — | < 52.6.0esr-72.20.2 | 52.6.0esr-72.20.2 | Jun 11, 2018 | A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. | ||
| CVE-2018-5102 | — | < 52.6.0esr-72.20.2 | 52.6.0esr-72.20.2 | Jun 11, 2018 | A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. | ||
| CVE-2018-5099 | — | < 52.6.0esr-72.20.2 | 52.6.0esr-72.20.2 | Jun 11, 2018 | A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects Thunderbird < 52.6, Firefox E | ||
| CVE-2018-5098 | — | < 52.6.0esr-72.20.2 | 52.6.0esr-72.20.2 | Jun 11, 2018 | A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. |
- CVE-2018-5157Jun 11, 2018affected < 52.8.0esr-72.32.1fixed 52.8.0esr-72.32.1
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Fi
- CVE-2018-5155Jun 11, 2018affected < 52.8.0esr-72.32.1fixed 52.8.0esr-72.32.1
A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
- CVE-2018-5154Jun 11, 2018affected < 52.8.0esr-72.32.1fixed 52.8.0esr-72.32.1
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
- CVE-2018-5150Jun 11, 2018affected < 52.8.0esr-72.32.1fixed 52.8.0esr-72.32.1
Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbi
- CVE-2018-5148Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
- CVE-2018-5147Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
- CVE-2018-5146Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
- CVE-2018-5145Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
- CVE-2018-5144Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
- CVE-2018-5131Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a web
- CVE-2018-5130Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
- CVE-2018-5129Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52
- CVE-2018-5127Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
- CVE-2018-5125Jun 11, 2018affected < 52.7.3esr-72.27.2fixed 52.7.3esr-72.27.2
Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox
- CVE-2018-5117Jun 11, 2018affected < 52.6.0esr-72.20.2fixed 52.6.0esr-72.20.2
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are o
- CVE-2018-5104Jun 11, 2018affected < 52.6.0esr-72.20.2fixed 52.6.0esr-72.20.2
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
- CVE-2018-5103Jun 11, 2018affected < 52.6.0esr-72.20.2fixed 52.6.0esr-72.20.2
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
- CVE-2018-5102Jun 11, 2018affected < 52.6.0esr-72.20.2fixed 52.6.0esr-72.20.2
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
- CVE-2018-5099Jun 11, 2018affected < 52.6.0esr-72.20.2fixed 52.6.0esr-72.20.2
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects Thunderbird < 52.6, Firefox E
- CVE-2018-5098Jun 11, 2018affected < 52.6.0esr-72.20.2fixed 52.6.0esr-72.20.2
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Page 2 of 15