VYPR

rpm package

suse/MozillaFirefox&distro=SUSE OpenStack Cloud 8

pkg:rpm/suse/MozillaFirefox&distro=SUSE%20OpenStack%20Cloud%208

Vulnerabilities (315)

  • CVE-2019-11743Sep 27, 2019
    affected < 60.9.0-109.86.1fixed 60.9.0-109.86.1

    Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure

  • CVE-2019-11744Sep 27, 2019
    affected < 60.9.0-109.86.1fixed 60.9.0-109.86.1

    Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside

  • CVE-2019-11746Sep 27, 2019
    affected < 60.9.0-109.86.1fixed 60.9.0-109.86.1

    A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ES

  • CVE-2019-11747Sep 27, 2019
    affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1

    The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Due to a bug, sites on the pre-l

  • CVE-2019-11748Sep 27, 2019
    affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1

    WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This

  • CVE-2019-11749Sep 27, 2019
    affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1

    A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of

  • CVE-2019-11750Sep 27, 2019
    affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1

    A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

  • CVE-2019-11751Sep 27, 2019
    affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1

    Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder.

  • CVE-2019-11752Sep 27, 2019
    affected < 60.9.0-109.86.1fixed 60.9.0-109.86.1

    It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Fir

  • CVE-2019-11753Sep 27, 2019
    affected < 60.9.0-109.86.1fixed 60.9.0-109.86.1

    The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance se

  • CVE-2019-15903Sep 4, 2019
    affected < 68.2.0-109.95.2fixed 68.2.0-109.95.2

    In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumnNumber) then resulted in a heap-based buffer over-read.

  • CVE-2019-9811Jul 23, 2019
    affected < 60.8.0-109.83.3fixed 60.8.0-109.83.3

    As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

  • CVE-2019-11708KEVJul 23, 2019
    affected < 60.7.2-109.80.1fixed 60.7.2-109.80.1

    Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result

  • CVE-2019-11709Jul 23, 2019
    affected < 60.8.0-109.83.3fixed 60.8.0-109.83.3

    Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner

  • CVE-2019-11710Jul 23, 2019
    affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1

    Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firef

  • CVE-2019-11711Jul 23, 2019
    affected < 60.8.0-109.83.3fixed 60.8.0-109.83.3

    When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, eve

  • CVE-2019-11712Jul 23, 2019
    affected < 60.8.0-109.83.3fixed 60.8.0-109.83.3

    POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderb

  • CVE-2019-11713Jul 23, 2019
    affected < 60.8.0-109.83.3fixed 60.8.0-109.83.3

    A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

  • CVE-2019-11714Jul 23, 2019
    affected < 68.1.0-109.89.1fixed 68.1.0-109.89.1

    Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.

  • CVE-2019-11715Jul 23, 2019
    affected < 60.8.0-109.83.3fixed 60.8.0-109.83.3

    Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

Page 13 of 16