VYPR

rpm package

suse/pipewire&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS

pkg:rpm/suse/pipewire&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Vulnerabilities (27)

  • CVE-2025-6430MedJun 24, 2025
    affected < 0.3.64-150500.3.7.2fixed 0.3.64-150500.3.7.2

    When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability was fixed i

  • CVE-2025-6429MedJun 24, 2025
    affected < 0.3.64-150500.3.7.2fixed 0.3.64-150500.3.7.2

    Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability was fixed in Fi

  • CVE-2025-6428MedJun 24, 2025
    affected < 0.3.64-150500.3.7.2fixed 0.3.64-150500.3.7.2

    When a URL was provided in a link querystring parameter, Firefox for Android would follow that URL instead of the correct URL, potentially leading to phishing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*. This vulnerability was f

  • CVE-2025-6427CriJun 24, 2025
    affected < 0.3.64-150500.3.7.2fixed 0.3.64-150500.3.7.2

    An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140 and Thunderbird 140.

  • CVE-2025-6426HigJun 24, 2025
    affected < 0.3.64-150500.3.7.2fixed 0.3.64-150500.3.7.2

    The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.*. This vulnerability was fixed in Firefox 140, Firefox ESR 128.12, Thunderbird 140, and Thunderb

  • CVE-2025-6425MedJun 24, 2025
    affected < 0.3.64-150500.3.7.2fixed 0.3.64-150500.3.7.2

    An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability was fixed in Firefox 140, Firefox ESR 115.2

  • CVE-2025-6424CriJun 24, 2025
    affected < 0.3.64-150500.3.7.2fixed 0.3.64-150500.3.7.2

    A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.

Page 2 of 2