rpm package
suse/MozillaThunderbird&distro=SUSE Package Hub 12
pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012
Vulnerabilities (265)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-9791 | Cri | 9.8 | < 60.6.1-82.1 | 60.6.1-82.1 | Apr 26, 2019 | The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for | |
| CVE-2019-9790 | Cri | 9.8 | < 60.6.1-82.1 | 60.6.1-82.1 | Apr 26, 2019 | A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60 | |
| CVE-2019-9788 | Cri | 9.8 | < 60.6.1-82.1 | 60.6.1-82.1 | Apr 26, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrar | |
| CVE-2018-18511 | Med | 4.3 | < 60.7.2-85.1 | 60.7.2-85.1 | Apr 26, 2019 | Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1. | |
| CVE-2018-18509 | Med | 5.3 | < 60.5.1-79.1 | 60.5.1-79.1 | Apr 26, 2019 | A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an emai | |
| CVE-2017-7777 | Hig | 8.8 | < 52.2-36.1 | 52.2-36.1 | Apr 15, 2019 | Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function. | |
| CVE-2017-7776 | Hig | 8.1 | < 52.2-36.1 | 52.2-36.1 | Apr 15, 2019 | Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. | |
| CVE-2017-7774 | Cri | 9.1 | < 52.2-36.1 | 52.2-36.1 | Apr 15, 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. | |
| CVE-2017-7773 | Hig | 8.8 | < 52.2-36.1 | 52.2-36.1 | Apr 15, 2019 | Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. | |
| CVE-2017-7771 | Hig | 8.1 | < 52.2-36.1 | 52.2-36.1 | Apr 15, 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. | |
| CVE-2017-7772 | Hig | 8.8 | < 52.2-36.1 | 52.2-36.1 | Apr 12, 2019 | Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. | |
| CVE-2018-18498 | Cri | 9.8 | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, an | |
| CVE-2018-18494 | Med | 6.5 | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerabili | |
| CVE-2018-18493 | Cri | 9.8 | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, F | |
| CVE-2018-18492 | Cri | 9.8 | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 6 | |
| CVE-2018-12405 | Cri | 9.8 | < 60.5.1-79.1 | 60.5.1-79.1 | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner | |
| CVE-2018-12393 | Hig | 7.5 | < 60.3.0-74.2 | 60.3.0-74.2 | Feb 28, 2019 | A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit build | |
| CVE-2018-12392 | Cri | 9.8 | < 60.3.0-74.2 | 60.3.0-74.2 | Feb 28, 2019 | When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3. | |
| CVE-2018-12391 | Hig | 8.8 | < 60.3.0-74.2 | 60.3.0-74.2 | Feb 28, 2019 | During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access | |
| CVE-2018-12390 | Cri | 9.8 | < 60.3.0-74.2 | 60.3.0-74.2 | Feb 28, 2019 | Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner |
- affected < 60.6.1-82.1fixed 60.6.1-82.1
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for
- affected < 60.6.1-82.1fixed 60.6.1-82.1
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60
- affected < 60.6.1-82.1fixed 60.6.1-82.1
Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrar
- affected < 60.7.2-85.1fixed 60.7.2-85.1
Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
- affected < 60.5.1-79.1fixed 60.5.1-79.1
A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even if the shown message contents aren't covered by the signature. The flaw allows an attacker to reuse a valid S/MIME signature to craft an emai
- affected < 52.2-36.1fixed 52.2-36.1
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
- affected < 52.2-36.1fixed 52.2-36.1
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
- affected < 52.2-36.1fixed 52.2-36.1
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
- affected < 52.2-36.1fixed 52.2-36.1
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
- affected < 52.2-36.1fixed 52.2-36.1
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
- affected < 52.2-36.1fixed 52.2-36.1
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
- affected < 60.5.1-79.1fixed 60.5.1-79.1
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, an
- affected < 60.5.1-79.1fixed 60.5.1-79.1
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerabili
- affected < 60.5.1-79.1fixed 60.5.1-79.1
A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, F
- affected < 60.5.1-79.1fixed 60.5.1-79.1
A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 6
- affected < 60.5.1-79.1fixed 60.5.1-79.1
Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner
- affected < 60.3.0-74.2fixed 60.3.0-74.2
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit build
- affected < 60.3.0-74.2fixed 60.3.0-74.2
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
- affected < 60.3.0-74.2fixed 60.3.0-74.2
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access
- affected < 60.3.0-74.2fixed 60.3.0-74.2
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulner
Page 3 of 14