VYPR

rpm package

suse/mozilla-nspr&distro=SUSE Linux Enterprise Server for SAP Applications 15

pkg:rpm/suse/mozilla-nspr&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015

Vulnerabilities (12)

  • CVE-2022-31741Dec 22, 2022
    affected < 4.34-150000.3.23.1fixed 4.34-150000.3.23.1

    A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

  • CVE-2020-12403May 27, 2021
    affected < 4.32-3.20.1fixed 4.32-3.20.1

    A flaw was found in the way CHACHA20-POLY1305 was implemented in NSS in versions before 3.55. When using multi-part Chacha20, it could cause out-of-bounds reads. This issue was fixed by explicitly disabling multi-part ChaCha20 (which was not functioning correctly) and strictly en

  • CVE-2021-23981Mar 31, 2021
    affected < 4.25.1-3.17.1fixed 4.25.1-3.17.1

    A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thun

  • CVE-2021-23982Mar 31, 2021
    affected < 4.25.1-3.17.1fixed 4.25.1-3.17.1

    Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and T

  • CVE-2021-23984Mar 31, 2021
    affected < 4.25.1-3.17.1fixed 4.25.1-3.17.1

    A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing cred

  • CVE-2021-23987Mar 31, 2021
    affected < 4.25.1-3.17.1fixed 4.25.1-3.17.1

    Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vuln

  • CVE-2020-6829Oct 28, 2020
    affected < 4.32-3.20.1fixed 4.32-3.20.1

    When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been com

  • CVE-2019-17006Oct 22, 2020
    affected < 4.25-3.12.1fixed 4.25-3.12.1

    In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow.

  • CVE-2020-25648Oct 20, 2020
    affected < 4.32-3.20.1fixed 4.32-3.20.1

    A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system ava

  • CVE-2020-12401Oct 8, 2020
    affected < 4.32-3.20.1fixed 4.32-3.20.1

    During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

  • CVE-2020-12400Oct 8, 2020
    affected < 4.32-3.20.1fixed 4.32-3.20.1

    When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

  • CVE-2020-12399Jul 9, 2020
    affected < 4.25-3.12.1fixed 4.25-3.12.1

    NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.