VYPR

rpm package

suse/MozillaFirefox-branding-SLE&distro=SUSE OpenStack Cloud 9

pkg:rpm/suse/MozillaFirefox-branding-SLE&distro=SUSE%20OpenStack%20Cloud%209

Vulnerabilities (69)

  • CVE-2020-12420HigJul 9, 2020
    affected < 78-35.3.1fixed 78-35.3.1

    When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

  • CVE-2020-12419HigJul 9, 2020
    affected < 78-35.3.1fixed 78-35.3.1

    When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, F

  • CVE-2020-12418MedJul 9, 2020
    affected < 78-35.3.1fixed 78-35.3.1

    Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.

  • CVE-2020-12417HigJul 9, 2020
    affected < 78-35.3.1fixed 78-35.3.1

    Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Fir

  • CVE-2020-12416HigJul 9, 2020
    affected < 78-35.3.1fixed 78-35.3.1

    A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78.

  • CVE-2020-12415MedJul 9, 2020
    affected < 78-35.3.1fixed 78-35.3.1

    When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 7

  • CVE-2020-12402MedJul 9, 2020
    affected < 78-35.3.1fixed 78-35.3.1

    During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the rec

  • CVE-2020-12424MedJul 9, 2020
    affected < 78-35.3.1fixed 78-35.3.1

    When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78.

  • CVE-2020-6813MedMar 25, 2020
    affected < 78-35.3.1fixed 78-35.3.1

    When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.

Page 4 of 4

VYPR — Vulnerability Intelligence