rpm package
suse/MozillaFirefox&distro=SUSE Linux Enterprise Server 12 SP2-BCL
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL
Vulnerabilities (505)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-38510 | — | < 91.3.0-112.80.2 | 91.3.0-112.80.2 | Dec 8, 2021 | The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Fire | ||
| CVE-2021-43536 | — | < 91.4.0-112.83.1 | 91.4.0-112.83.1 | Dec 8, 2021 | Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | ||
| CVE-2021-43537 | — | < 91.4.0-112.83.1 | 91.4.0-112.83.1 | Dec 8, 2021 | An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | ||
| CVE-2021-43538 | — | < 91.4.0-112.83.1 | 91.4.0-112.83.1 | Dec 8, 2021 | By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < | ||
| CVE-2021-43539 | — | < 91.4.0-112.83.1 | 91.4.0-112.83.1 | Dec 8, 2021 | Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird | ||
| CVE-2021-43541 | — | < 91.4.0-112.83.1 | 91.4.0-112.83.1 | Dec 8, 2021 | When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | ||
| CVE-2021-43542 | — | < 91.4.0-112.83.1 | 91.4.0-112.83.1 | Dec 8, 2021 | Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | ||
| CVE-2021-43543 | — | < 91.4.0-112.83.1 | 91.4.0-112.83.1 | Dec 8, 2021 | Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | ||
| CVE-2021-43545 | — | < 91.4.0-112.83.1 | 91.4.0-112.83.1 | Dec 8, 2021 | Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | ||
| CVE-2021-43546 | — | < 91.4.0-112.83.1 | 91.4.0-112.83.1 | Dec 8, 2021 | It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | ||
| CVE-2021-29991 | — | < 91.1.0-112.71.1 | 91.1.0-112.71.1 | Nov 3, 2021 | Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1. | ||
| CVE-2021-38492 | — | < 91.1.0-112.71.1 | 91.1.0-112.71.1 | Nov 3, 2021 | When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected. | ||
| CVE-2021-38495 | — | < 91.1.0-112.71.1 | 91.1.0-112.71.1 | Nov 3, 2021 | Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91 | ||
| CVE-2021-38496 | — | < 91.2.0-112.74.1 | 91.2.0-112.74.1 | Nov 3, 2021 | During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firef | ||
| CVE-2021-38497 | — | < 91.2.0-112.74.1 | 91.2.0-112.74.1 | Nov 3, 2021 | Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2. | ||
| CVE-2021-38498 | — | < 91.2.0-112.74.1 | 91.2.0-112.74.1 | Nov 3, 2021 | During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2. | ||
| CVE-2021-38500 | — | < 91.2.0-112.74.1 | 91.2.0-112.74.1 | Nov 3, 2021 | Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thun | ||
| CVE-2021-38501 | — | < 91.2.0-112.74.1 | 91.2.0-112.74.1 | Nov 3, 2021 | Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Fire | ||
| CVE-2021-29980 | — | < 78.13.0-112.68.1 | 78.13.0-112.68.1 | Aug 17, 2021 | Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91. | ||
| CVE-2021-29981 | — | < 91.1.0-112.71.1 | 91.1.0-112.71.1 | Aug 17, 2021 | An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code that would lead to a potentially exploitable crash. This vulnerability affects Firefox < 91 and Thunderbird < 91. |
- CVE-2021-38510Dec 8, 2021affected < 91.3.0-112.80.2fixed 91.3.0-112.80.2
The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Fire
- CVE-2021-43536Dec 8, 2021affected < 91.4.0-112.83.1fixed 91.4.0-112.83.1
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-43537Dec 8, 2021affected < 91.4.0-112.83.1fixed 91.4.0-112.83.1
An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-43538Dec 8, 2021affected < 91.4.0-112.83.1fixed 91.4.0-112.83.1
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR <
- CVE-2021-43539Dec 8, 2021affected < 91.4.0-112.83.1fixed 91.4.0-112.83.1
Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird
- CVE-2021-43541Dec 8, 2021affected < 91.4.0-112.83.1fixed 91.4.0-112.83.1
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-43542Dec 8, 2021affected < 91.4.0-112.83.1fixed 91.4.0-112.83.1
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-43543Dec 8, 2021affected < 91.4.0-112.83.1fixed 91.4.0-112.83.1
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-43545Dec 8, 2021affected < 91.4.0-112.83.1fixed 91.4.0-112.83.1
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-43546Dec 8, 2021affected < 91.4.0-112.83.1fixed 91.4.0-112.83.1
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
- CVE-2021-29991Nov 3, 2021affected < 91.1.0-112.71.1fixed 91.1.0-112.71.1
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.
- CVE-2021-38492Nov 3, 2021affected < 91.1.0-112.71.1fixed 91.1.0-112.71.1
When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.
- CVE-2021-38495Nov 3, 2021affected < 91.1.0-112.71.1fixed 91.1.0-112.71.1
Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91
- CVE-2021-38496Nov 3, 2021affected < 91.2.0-112.74.1fixed 91.2.0-112.74.1
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firef
- CVE-2021-38497Nov 3, 2021affected < 91.2.0-112.74.1fixed 91.2.0-112.74.1
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
- CVE-2021-38498Nov 3, 2021affected < 91.2.0-112.74.1fixed 91.2.0-112.74.1
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
- CVE-2021-38500Nov 3, 2021affected < 91.2.0-112.74.1fixed 91.2.0-112.74.1
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thun
- CVE-2021-38501Nov 3, 2021affected < 91.2.0-112.74.1fixed 91.2.0-112.74.1
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Fire
- CVE-2021-29980Aug 17, 2021affected < 78.13.0-112.68.1fixed 78.13.0-112.68.1
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
- CVE-2021-29981Aug 17, 2021affected < 91.1.0-112.71.1fixed 91.1.0-112.71.1
An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code that would lead to a potentially exploitable crash. This vulnerability affects Firefox < 91 and Thunderbird < 91.
Page 11 of 26