VYPR

rpm package

suse/MozillaThunderbird&distro=SUSE Package Hub 12

pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012

Vulnerabilities (265)

  • CVE-2019-11709Jul 23, 2019
    affected < 60.8.0-88.1fixed 60.8.0-88.1

    Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner

  • CVE-2019-11711Jul 23, 2019
    affected < 60.8.0-88.1fixed 60.8.0-88.1

    When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, eve

  • CVE-2019-11712Jul 23, 2019
    affected < 60.8.0-88.1fixed 60.8.0-88.1

    POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderb

  • CVE-2019-11713Jul 23, 2019
    affected < 60.8.0-88.1fixed 60.8.0-88.1

    A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

  • CVE-2019-11715Jul 23, 2019
    affected < 60.8.0-88.1fixed 60.8.0-88.1

    Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

  • CVE-2019-11717Jul 23, 2019
    affected < 60.8.0-88.1fixed 60.8.0-88.1

    A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

  • CVE-2019-11719Jul 23, 2019
    affected < 60.8.0-88.1fixed 60.8.0-88.1

    When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68,

  • CVE-2019-11729Jul 23, 2019
    affected < 60.8.0-88.1fixed 60.8.0-88.1

    Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

  • CVE-2019-11730Jul 23, 2019
    affected < 60.8.0-88.1fixed 60.8.0-88.1

    A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these

  • CVE-2019-5785Jun 27, 2019
    affected < 60.5.1-79.1fixed 60.5.1-79.1

    Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

  • CVE-2019-5798May 23, 2019
    affected < 60.7.2-85.1fixed 60.7.2-85.1

    Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

  • CVE-2019-9801Apr 26, 2019
    affected < 60.6.1-82.1fixed 60.6.1-82.1

    Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Win

  • CVE-2019-9797Apr 26, 2019
    affected < 60.7.2-85.1fixed 60.7.2-85.1

    Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.

  • CVE-2019-9796Apr 26, 2019
    affected < 60.6.1-82.1fixed 60.6.1-82.1

    A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver

  • CVE-2019-9795Apr 26, 2019
    affected < 60.6.1-82.1fixed 60.6.1-82.1

    A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

  • CVE-2019-9794Apr 26, 2019
    affected < 60.6.1-82.1fixed 60.6.1-82.1

    A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is co

  • CVE-2019-9793Apr 26, 2019
    affected < 60.6.1-82.1fixed 60.6.1-82.1

    A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will inf

  • CVE-2019-9792Apr 26, 2019
    affected < 60.6.1-82.1fixed 60.6.1-82.1

    The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability a

  • CVE-2019-9791Apr 26, 2019
    affected < 60.6.1-82.1fixed 60.6.1-82.1

    The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for

  • CVE-2019-9790Apr 26, 2019
    affected < 60.6.1-82.1fixed 60.6.1-82.1

    A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60

Page 2 of 14