VYPR

rpm package

suse/MozillaFirefox&distro=SUSE Linux Enterprise Server 15 SP6-LTSS

pkg:rpm/suse/MozillaFirefox&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Vulnerabilities (121)

  • CVE-2026-12298MedJun 16, 2026
    affected < 140.12.0-150200.152.242.1fixed 140.12.0-150200.152.242.1

    Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12297Jun 16, 2026
    affected < 140.12.0-150200.152.242.1fixed 140.12.0-150200.152.242.1

    Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12296Jun 16, 2026
    affected < 140.12.0-150200.152.242.1fixed 140.12.0-150200.152.242.1

    Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12295Jun 16, 2026
    affected < 140.12.0-150200.152.242.1fixed 140.12.0-150200.152.242.1

    Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12294Jun 16, 2026
    affected < 140.12.0-150200.152.242.1fixed 140.12.0-150200.152.242.1

    Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12292Jun 16, 2026
    affected < 140.12.0-150200.152.242.1fixed 140.12.0-150200.152.242.1

    Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12291Jun 16, 2026
    affected < 140.12.0-150200.152.242.1fixed 140.12.0-150200.152.242.1

    Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12290Jun 16, 2026
    affected < 140.12.0-150200.152.242.1fixed 140.12.0-150200.152.242.1

    Memory safety bug fixed in Thunderbird 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12289HigJun 16, 2026
    affected < 140.12.0-150200.152.242.1fixed 140.12.0-150200.152.242.1

    Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-5734CriApr 7, 2026
    affected < 140.9.1-150200.152.228.1fixed 140.9.1-150200.152.228.1

    Memory safety bugs present in Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This

  • CVE-2026-5732HigApr 7, 2026
    affected < 140.9.1-150200.152.228.1fixed 140.9.1-150200.152.228.1

    Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability was fixed in Firefox 149.0.2, Firefox ESR 140.9.1, Thunderbird 149.0.2, and Thunderbird 140.9.1.

  • CVE-2026-5731CriApr 7, 2026
    affected < 140.9.1-150200.152.228.1fixed 140.9.1-150200.152.228.1

    Memory safety bugs present in Firefox ESR 115.34.0, Firefox ESR 140.9.0, Thunderbird ESR 140.9.0, Firefox 149.0.1 and Thunderbird 149.0.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run

  • CVE-2026-4721CriMar 24, 2026
    affected < 140.9.0-150200.152.225.1fixed 140.9.0-150200.152.225.1

    Memory safety bugs present in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary cod

  • CVE-2026-4720CriMar 24, 2026
    affected < 140.9.0-150200.152.225.1fixed 140.9.0-150200.152.225.1

    Memory safety bugs present in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerabilit

  • CVE-2026-4719HigMar 24, 2026
    affected < 140.9.0-150200.152.225.1fixed 140.9.0-150200.152.225.1

    Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

  • CVE-2026-4718HigMar 24, 2026
    affected < 140.9.0-150200.152.225.1fixed 140.9.0-150200.152.225.1

    Undefined behavior in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

  • CVE-2026-4717CriMar 24, 2026
    affected < 140.9.0-150200.152.225.1fixed 140.9.0-150200.152.225.1

    Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

  • CVE-2026-4716CriMar 24, 2026
    affected < 140.9.0-150200.152.225.1fixed 140.9.0-150200.152.225.1

    Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

  • CVE-2026-4715CriMar 24, 2026
    affected < 140.9.0-150200.152.225.1fixed 140.9.0-150200.152.225.1

    Uninitialized memory in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

  • CVE-2026-4714HigMar 24, 2026
    affected < 140.9.0-150200.152.225.1fixed 140.9.0-150200.152.225.1

    Incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Page 2 of 7