rpm package
suse/MozillaThunderbird&distro=SUSE Package Hub 12
pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012
Vulnerabilities (265)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-9788 | — | < 60.6.1-82.1 | 60.6.1-82.1 | Apr 26, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrar | ||
| CVE-2018-18511 | — | < 60.7.2-85.1 | 60.7.2-85.1 | Apr 26, 2019 | Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1. | ||
| CVE-2018-18509 | — | < 60.5.1-79.1 | 60.5.1-79.1 | Apr 26, 2019 | A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an emai | ||
| CVE-2019-9810 | — | < 60.6.1-82.1 | 60.6.1-82.1 | Apr 26, 2019 | Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1. | ||
| CVE-2019-9813 | — | < 60.6.1-82.1 | 60.6.1-82.1 | Apr 26, 2019 | Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1. | ||
| CVE-2017-7777 | — | < 52.2-36.1 | 52.2-36.1 | Apr 12, 2019 | Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. | ||
| CVE-2017-7776 | — | < 52.2-36.1 | 52.2-36.1 | Apr 12, 2019 | Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. | ||
| CVE-2017-7774 | — | < 52.2-36.1 | 52.2-36.1 | Apr 12, 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. | ||
| CVE-2017-7773 | — | < 52.2-36.1 | 52.2-36.1 | Apr 12, 2019 | Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. | ||
| CVE-2017-7771 | — | < 52.2-36.1 | 52.2-36.1 | Apr 12, 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. | ||
| CVE-2017-7772 | — | < 52.2-36.1 | 52.2-36.1 | Apr 12, 2019 | Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. | ||
| CVE-2018-18498 | — | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, an | ||
| CVE-2018-18494 | — | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerabili | ||
| CVE-2018-18493 | — | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, F | ||
| CVE-2018-18492 | — | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 6 | ||
| CVE-2018-12405 | — | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner | ||
| CVE-2018-12393 | — | < 60.3.0-74.2 | 60.3.0-74.2 | Feb 28, 2019 | A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit build | ||
| CVE-2018-12392 | — | < 60.3.0-74.2 | 60.3.0-74.2 | Feb 28, 2019 | When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3. | ||
| CVE-2018-12391 | — | < 60.3.0-74.2 | 60.3.0-74.2 | Feb 28, 2019 | During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access | ||
| CVE-2018-12390 | — | < 60.3.0-74.2 | 60.3.0-74.2 | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner |
- CVE-2019-9788Apr 26, 2019affected < 60.6.1-82.1fixed 60.6.1-82.1
Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrar
- CVE-2018-18511Apr 26, 2019affected < 60.7.2-85.1fixed 60.7.2-85.1
Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
- CVE-2018-18509Apr 26, 2019affected < 60.5.1-79.1fixed 60.5.1-79.1
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an emai
- CVE-2019-9810Apr 26, 2019affected < 60.6.1-82.1fixed 60.6.1-82.1
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
- CVE-2019-9813Apr 26, 2019affected < 60.6.1-82.1fixed 60.6.1-82.1
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
- CVE-2017-7777Apr 12, 2019affected < 52.2-36.1fixed 52.2-36.1
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
- CVE-2017-7776Apr 12, 2019affected < 52.2-36.1fixed 52.2-36.1
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
- CVE-2017-7774Apr 12, 2019affected < 52.2-36.1fixed 52.2-36.1
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
- CVE-2017-7773Apr 12, 2019affected < 52.2-36.1fixed 52.2-36.1
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
- CVE-2017-7771Apr 12, 2019affected < 52.2-36.1fixed 52.2-36.1
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
- CVE-2017-7772Apr 12, 2019affected < 52.2-36.1fixed 52.2-36.1
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
- CVE-2018-18498Feb 28, 2019affected < 60.5.1-79.1fixed 60.5.1-79.1
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, an
- CVE-2018-18494Feb 28, 2019affected < 60.5.1-79.1fixed 60.5.1-79.1
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerabili
- CVE-2018-18493Feb 28, 2019affected < 60.5.1-79.1fixed 60.5.1-79.1
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, F
- CVE-2018-18492Feb 28, 2019affected < 60.5.1-79.1fixed 60.5.1-79.1
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 6
- CVE-2018-12405Feb 28, 2019affected < 60.5.1-79.1fixed 60.5.1-79.1
Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner
- CVE-2018-12393Feb 28, 2019affected < 60.3.0-74.2fixed 60.3.0-74.2
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit build
- CVE-2018-12392Feb 28, 2019affected < 60.3.0-74.2fixed 60.3.0-74.2
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
- CVE-2018-12391Feb 28, 2019affected < 60.3.0-74.2fixed 60.3.0-74.2
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access
- CVE-2018-12390Feb 28, 2019affected < 60.3.0-74.2fixed 60.3.0-74.2
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner
Page 3 of 14