[SUSE-SU-2024:2876-1] Security update for MozillaFirefox

Severity Important
CVEs 28

Security update for MozillaFirefox

This update for MozillaFirefox fixes the following issues:

Update to Firefox Extended Support Release 128.1.0 ESR (MFSA 2024-35, bsc#1228648)

  • CVE-2024-7518: Fullscreen notification dialog can be obscured by document
  • CVE-2024-7519: Out of bounds memory access in graphics shared memory handling
  • CVE-2024-7520: Type confusion in WebAssembly
  • CVE-2024-7521: Incomplete WebAssembly exception handing
  • CVE-2024-7522: Out of bounds read in editor component
  • CVE-2024-7524: CSP strict-dynamic bypass using web-compatibility shims
  • CVE-2024-7525: Missing permission check when creating a StreamFilter
  • CVE-2024-7526: Uninitialized memory used by WebGL
  • CVE-2024-7527: Use-after-free in JavaScript garbage collection
  • CVE-2024-7528: Use-after-free in IndexedDB
  • CVE-2024-7529: Document content could partially obscure security prompts
  • CVE-2024-7531: PK11_Encrypt using CKM_CHACHA20 can reveal plaintext on Intel
Source # ID Name URL
Suse SUSE ratings https://www.suse.com/support/security/rating/
Suse URL of this CSAF notice https://ftp.suse.com/pub/projects/security/csaf/suse-su-2024_2876-1.json
Suse URL for SUSE-SU-2024:2876-1 https://www.suse.com/support/update/announcement/2024/suse-su-20242876-1/
Suse E-Mail link for SUSE-SU-2024:2876-1 https://lists.suse.com/pipermail/sle-updates/2024-August/036415.html
Bugzilla SUSE Bug 1226316 https://bugzilla.suse.com/1226316
Bugzilla SUSE Bug 1228648 https://bugzilla.suse.com/1228648
CVE SUSE CVE CVE-2024-6600 page https://www.suse.com/security/cve/CVE-2024-6600/
CVE SUSE CVE CVE-2024-6601 page https://www.suse.com/security/cve/CVE-2024-6601/
CVE SUSE CVE CVE-2024-6602 page https://www.suse.com/security/cve/CVE-2024-6602/
CVE SUSE CVE CVE-2024-6603 page https://www.suse.com/security/cve/CVE-2024-6603/
CVE SUSE CVE CVE-2024-6604 page https://www.suse.com/security/cve/CVE-2024-6604/
CVE SUSE CVE CVE-2024-6605 page https://www.suse.com/security/cve/CVE-2024-6605/
CVE SUSE CVE CVE-2024-6606 page https://www.suse.com/security/cve/CVE-2024-6606/
CVE SUSE CVE CVE-2024-6607 page https://www.suse.com/security/cve/CVE-2024-6607/
CVE SUSE CVE CVE-2024-6608 page https://www.suse.com/security/cve/CVE-2024-6608/
CVE SUSE CVE CVE-2024-6609 page https://www.suse.com/security/cve/CVE-2024-6609/
CVE SUSE CVE CVE-2024-6610 page https://www.suse.com/security/cve/CVE-2024-6610/
CVE SUSE CVE CVE-2024-6611 page https://www.suse.com/security/cve/CVE-2024-6611/
CVE SUSE CVE CVE-2024-6612 page https://www.suse.com/security/cve/CVE-2024-6612/
CVE SUSE CVE CVE-2024-6613 page https://www.suse.com/security/cve/CVE-2024-6613/
CVE SUSE CVE CVE-2024-6614 page https://www.suse.com/security/cve/CVE-2024-6614/
CVE SUSE CVE CVE-2024-6615 page https://www.suse.com/security/cve/CVE-2024-6615/
CVE SUSE CVE CVE-2024-7518 page https://www.suse.com/security/cve/CVE-2024-7518/
CVE SUSE CVE CVE-2024-7519 page https://www.suse.com/security/cve/CVE-2024-7519/
CVE SUSE CVE CVE-2024-7520 page https://www.suse.com/security/cve/CVE-2024-7520/
CVE SUSE CVE CVE-2024-7521 page https://www.suse.com/security/cve/CVE-2024-7521/
CVE SUSE CVE CVE-2024-7522 page https://www.suse.com/security/cve/CVE-2024-7522/
CVE SUSE CVE CVE-2024-7524 page https://www.suse.com/security/cve/CVE-2024-7524/
CVE SUSE CVE CVE-2024-7525 page https://www.suse.com/security/cve/CVE-2024-7525/
CVE SUSE CVE CVE-2024-7526 page https://www.suse.com/security/cve/CVE-2024-7526/
CVE SUSE CVE CVE-2024-7527 page https://www.suse.com/security/cve/CVE-2024-7527/
CVE SUSE CVE CVE-2024-7528 page https://www.suse.com/security/cve/CVE-2024-7528/
CVE SUSE CVE CVE-2024-7529 page https://www.suse.com/security/cve/CVE-2024-7529/
CVE SUSE CVE CVE-2024-7531 page https://www.suse.com/security/cve/CVE-2024-7531/
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...