VYPR

rpm package

suse/MozillaFirefox-branding-SLE&distro=SUSE OpenStack Cloud 7

pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20OpenStack%20Cloud%207

Vulnerabilities (65)

  • CVE-2018-12379Oct 18, 2018
    affected < 60-32.3.1fixed 60-32.3.1

    When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in or

  • CVE-2018-12378Oct 18, 2018
    affected < 60-32.3.1fixed 60-32.3.1

    A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thund

  • CVE-2018-12377Oct 18, 2018
    affected < 60-32.3.1fixed 60-32.3.1

    A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and

  • CVE-2018-12376Oct 18, 2018
    affected < 60-32.3.1fixed 60-32.3.1

    Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2,

  • CVE-2017-16541MedNov 4, 2017
    affected < 60-32.3.1fixed 60-32.3.1

    Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.

Page 4 of 4