rpm package
suse/MozillaFirefox&distro=SUSE Linux Enterprise Server 12 SP5
pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5
Vulnerabilities (593)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-11744 | — | < 60.9.0-109.86.1 | 60.9.0-109.86.1 | Sep 27, 2019 | Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside | ||
| CVE-2019-11746 | — | < 60.9.0-109.86.1 | 60.9.0-109.86.1 | Sep 27, 2019 | A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ES | ||
| CVE-2019-11747 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Sep 27, 2019 | The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Due to a bug, sites on the pre-l | ||
| CVE-2019-11748 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Sep 27, 2019 | WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This | ||
| CVE-2019-11749 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Sep 27, 2019 | A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of | ||
| CVE-2019-11750 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Sep 27, 2019 | A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1. | ||
| CVE-2019-11751 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Sep 27, 2019 | Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder. | ||
| CVE-2019-11752 | — | < 60.9.0-109.86.1 | 60.9.0-109.86.1 | Sep 27, 2019 | It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Fir | ||
| CVE-2019-11753 | — | < 60.9.0-109.86.1 | 60.9.0-109.86.1 | Sep 27, 2019 | The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance se | ||
| CVE-2019-15903 | — | < 68.2.0-109.95.2 | 68.2.0-109.95.2 | Sep 4, 2019 | In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read. | ||
| CVE-2019-9811 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | ||
| CVE-2019-11709 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner | ||
| CVE-2019-11710 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firef | ||
| CVE-2019-11711 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, eve | ||
| CVE-2019-11712 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderb | ||
| CVE-2019-11713 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | ||
| CVE-2019-11714 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68. | ||
| CVE-2019-11715 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | ||
| CVE-2019-11716 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowin | ||
| CVE-2019-11717 | — | < 68.1.0-109.89.1 | 68.1.0-109.89.1 | Jul 23, 2019 | A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. |
- CVE-2019-11744Sep 27, 2019affected < 60.9.0-109.86.1fixed 60.9.0-109.86.1
Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside
- CVE-2019-11746Sep 27, 2019affected < 60.9.0-109.86.1fixed 60.9.0-109.86.1
A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ES
- CVE-2019-11747Sep 27, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Due to a bug, sites on the pre-l
- CVE-2019-11748Sep 27, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This
- CVE-2019-11749Sep 27, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of
- CVE-2019-11750Sep 27, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
- CVE-2019-11751Sep 27, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder.
- CVE-2019-11752Sep 27, 2019affected < 60.9.0-109.86.1fixed 60.9.0-109.86.1
It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Fir
- CVE-2019-11753Sep 27, 2019affected < 60.9.0-109.86.1fixed 60.9.0-109.86.1
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance se
- CVE-2019-15903Sep 4, 2019affected < 68.2.0-109.95.2fixed 68.2.0-109.95.2
In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.
- CVE-2019-9811Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
- CVE-2019-11709Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner
- CVE-2019-11710Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firef
- CVE-2019-11711Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, eve
- CVE-2019-11712Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderb
- CVE-2019-11713Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
- CVE-2019-11714Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.
- CVE-2019-11715Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
- CVE-2019-11716Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowin
- CVE-2019-11717Jul 23, 2019affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Page 27 of 30