opensuse-su-2016:1769-1
Vulnerability from csaf_opensuse
Published
2016-07-10 18:30
Modified
2016-07-10 18:30
Summary
Security update for Mozilla Thunderbird
Notes
Title of the patch
Security update for Mozilla Thunderbird
Description of the patch
This update contains Mozilla Thunderbird 45.2. (boo#983549)
It fixes security issues mostly affecting the e-mail program when used in a browser context, such as viewing a web page or HTMl formatted e-mail.
The following vulnerabilities were fixed:
- CVE-2016-2818, CVE-2016-2815: Memory safety bugs (boo#983549, MFSA2016-49)
Contains the following security fixes from the 45.1 release: (boo#977333)
- CVE-2016-2806, CVE-2016-2807: Miscellaneous memory safety hazards (boo#977375, boo#977376, MFSA 2016-39)
Contains the following security fixes from the 45.0 release: (boo#969894)
- CVE-2016-1952, CVE-2016-1953: Miscellaneous memory safety hazards (MFSA 2016-16)
- CVE-2016-1954: Local file overwriting and potential privilege escalation through CSP reports (MFSA 2016-17)
- CVE-2016-1955: CSP reports fail to strip location information for embedded iframe pages (MFSA 2016-18)
- CVE-2016-1956: Linux video memory DOS with Intel drivers (MFSA 2016-19)
- CVE-2016-1957: Memory leak in libstagefright when deleting an array during MP4 processing (MFSA 2016-20)
- CVE-2016-1960: Use-after-free in HTML5 string parser (MFSA 2016-23)
- CVE-2016-1961: Use-after-free in SetBody (MFSA 2016-24)
- CVE-2016-1964: Use-after-free during XML transformations (MFSA 2016-27)
- CVE-2016-1974: Out-of-bounds read in HTML parser following a failed allocation (MFSA 2016-34)
The graphite font shaping library was disabled, addressing the following font vulnerabilities:
- MFSA 2016-37/CVE-2016-1977/CVE-2016-2790/CVE-2016-2791/
CVE-2016-2792/CVE-2016-2793/CVE-2016-2794/CVE-2016-2795/
CVE-2016-2796/CVE-2016-2797/CVE-2016-2798/CVE-2016-2799/
CVE-2016-2800/CVE-2016-2801/CVE-2016-2802
The following tracked packaging changes are included:
- fix build issues with gcc/binutils combination used in Leap 42.2 (boo#984637)
- gcc6 fixes (boo#986162)
- running on 48bit va aarch64 (boo#984126)
Patchnames
openSUSE-2016-851
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "important" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for Mozilla Thunderbird", "title": "Title of the patch" }, { "category": "description", "text": "This update contains Mozilla Thunderbird 45.2. (boo#983549)\n\nIt fixes security issues mostly affecting the e-mail program when used in a browser context, such as viewing a web page or HTMl formatted e-mail.\n\nThe following vulnerabilities were fixed:\n\n- CVE-2016-2818, CVE-2016-2815: Memory safety bugs (boo#983549, MFSA2016-49)\n\nContains the following security fixes from the 45.1 release: (boo#977333)\n\n- CVE-2016-2806, CVE-2016-2807: Miscellaneous memory safety hazards (boo#977375, boo#977376, MFSA 2016-39)\n\nContains the following security fixes from the 45.0 release: (boo#969894)\n\n- CVE-2016-1952, CVE-2016-1953: Miscellaneous memory safety hazards (MFSA 2016-16)\n- CVE-2016-1954: Local file overwriting and potential privilege escalation through CSP reports (MFSA 2016-17)\n- CVE-2016-1955: CSP reports fail to strip location information for embedded iframe pages (MFSA 2016-18)\n- CVE-2016-1956: Linux video memory DOS with Intel drivers (MFSA 2016-19)\n- CVE-2016-1957: Memory leak in libstagefright when deleting an array during MP4 processing (MFSA 2016-20)\n- CVE-2016-1960: Use-after-free in HTML5 string parser (MFSA 2016-23)\n- CVE-2016-1961: Use-after-free in SetBody (MFSA 2016-24)\n- CVE-2016-1964: Use-after-free during XML transformations (MFSA 2016-27)\n- CVE-2016-1974: Out-of-bounds read in HTML parser following a failed allocation (MFSA 2016-34)\n\nThe graphite font shaping library was disabled, addressing the following font vulnerabilities:\n\n- MFSA 2016-37/CVE-2016-1977/CVE-2016-2790/CVE-2016-2791/\n CVE-2016-2792/CVE-2016-2793/CVE-2016-2794/CVE-2016-2795/\n CVE-2016-2796/CVE-2016-2797/CVE-2016-2798/CVE-2016-2799/\n CVE-2016-2800/CVE-2016-2801/CVE-2016-2802\n\nThe following tracked packaging changes are included:\n\n- fix build issues with gcc/binutils combination used in Leap 42.2 (boo#984637)\n- gcc6 fixes (boo#986162)\n- running on 48bit va aarch64 (boo#984126)", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-2016-851", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2016_1769-1.json" }, { "category": "self", "summary": "URL for openSUSE-SU-2016:1769-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5" }, { "category": "self", "summary": "E-Mail link for openSUSE-SU-2016:1769-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5" }, { "category": "self", "summary": "SUSE Bug 969894", "url": "https://bugzilla.suse.com/969894" }, { "category": "self", "summary": "SUSE Bug 977333", "url": "https://bugzilla.suse.com/977333" }, { "category": "self", "summary": "SUSE Bug 977375", "url": "https://bugzilla.suse.com/977375" }, { "category": "self", "summary": "SUSE Bug 977376", "url": "https://bugzilla.suse.com/977376" }, { "category": "self", "summary": "SUSE Bug 983549", "url": "https://bugzilla.suse.com/983549" }, { "category": "self", "summary": "SUSE Bug 984126", "url": "https://bugzilla.suse.com/984126" }, { "category": "self", "summary": "SUSE Bug 984637", "url": "https://bugzilla.suse.com/984637" }, { "category": "self", "summary": "SUSE Bug 986162", "url": "https://bugzilla.suse.com/986162" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1952 page", "url": "https://www.suse.com/security/cve/CVE-2016-1952/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1953 page", "url": "https://www.suse.com/security/cve/CVE-2016-1953/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1954 page", "url": "https://www.suse.com/security/cve/CVE-2016-1954/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1955 page", "url": "https://www.suse.com/security/cve/CVE-2016-1955/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1956 page", "url": "https://www.suse.com/security/cve/CVE-2016-1956/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1957 page", "url": "https://www.suse.com/security/cve/CVE-2016-1957/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1960 page", "url": "https://www.suse.com/security/cve/CVE-2016-1960/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1961 page", "url": "https://www.suse.com/security/cve/CVE-2016-1961/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1964 page", "url": "https://www.suse.com/security/cve/CVE-2016-1964/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1974 page", "url": "https://www.suse.com/security/cve/CVE-2016-1974/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-1977 page", "url": "https://www.suse.com/security/cve/CVE-2016-1977/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2790 page", "url": "https://www.suse.com/security/cve/CVE-2016-2790/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2791 page", "url": "https://www.suse.com/security/cve/CVE-2016-2791/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2792 page", "url": "https://www.suse.com/security/cve/CVE-2016-2792/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2793 page", "url": "https://www.suse.com/security/cve/CVE-2016-2793/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2794 page", "url": "https://www.suse.com/security/cve/CVE-2016-2794/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2795 page", "url": "https://www.suse.com/security/cve/CVE-2016-2795/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2796 page", "url": "https://www.suse.com/security/cve/CVE-2016-2796/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2797 page", "url": "https://www.suse.com/security/cve/CVE-2016-2797/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2798 page", "url": "https://www.suse.com/security/cve/CVE-2016-2798/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2799 page", "url": "https://www.suse.com/security/cve/CVE-2016-2799/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2800 page", "url": "https://www.suse.com/security/cve/CVE-2016-2800/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2801 page", "url": "https://www.suse.com/security/cve/CVE-2016-2801/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2802 page", "url": "https://www.suse.com/security/cve/CVE-2016-2802/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2806 page", "url": "https://www.suse.com/security/cve/CVE-2016-2806/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2807 page", "url": "https://www.suse.com/security/cve/CVE-2016-2807/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2815 page", "url": "https://www.suse.com/security/cve/CVE-2016-2815/" }, { "category": "self", "summary": "SUSE CVE CVE-2016-2818 page", "url": "https://www.suse.com/security/cve/CVE-2016-2818/" } ], "title": "Security update for Mozilla Thunderbird", "tracking": { "current_release_date": "2016-07-10T18:30:29Z", "generator": { "date": "2016-07-10T18:30:29Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2016:1769-1", "initial_release_date": "2016-07-10T18:30:29Z", "revision_history": [ { "date": "2016-07-10T18:30:29Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "MozillaThunderbird-45.2-6.1.aarch64", "product": { "name": "MozillaThunderbird-45.2-6.1.aarch64", "product_id": "MozillaThunderbird-45.2-6.1.aarch64" } }, { "category": "product_version", "name": "MozillaThunderbird-devel-45.2-6.1.aarch64", "product": { "name": "MozillaThunderbird-devel-45.2-6.1.aarch64", "product_id": "MozillaThunderbird-devel-45.2-6.1.aarch64" } }, { "category": "product_version", "name": "MozillaThunderbird-translations-common-45.2-6.1.aarch64", "product": { "name": "MozillaThunderbird-translations-common-45.2-6.1.aarch64", "product_id": "MozillaThunderbird-translations-common-45.2-6.1.aarch64" } }, { "category": "product_version", "name": "MozillaThunderbird-translations-other-45.2-6.1.aarch64", "product": { "name": "MozillaThunderbird-translations-other-45.2-6.1.aarch64", "product_id": "MozillaThunderbird-translations-other-45.2-6.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "MozillaThunderbird-45.2-6.1.s390x", "product": { "name": "MozillaThunderbird-45.2-6.1.s390x", "product_id": "MozillaThunderbird-45.2-6.1.s390x" } }, { "category": "product_version", "name": "MozillaThunderbird-devel-45.2-6.1.s390x", "product": { "name": "MozillaThunderbird-devel-45.2-6.1.s390x", "product_id": "MozillaThunderbird-devel-45.2-6.1.s390x" } }, { "category": "product_version", "name": "MozillaThunderbird-translations-common-45.2-6.1.s390x", "product": { "name": "MozillaThunderbird-translations-common-45.2-6.1.s390x", "product_id": "MozillaThunderbird-translations-common-45.2-6.1.s390x" } }, { "category": "product_version", "name": "MozillaThunderbird-translations-other-45.2-6.1.s390x", "product": { "name": "MozillaThunderbird-translations-other-45.2-6.1.s390x", "product_id": "MozillaThunderbird-translations-other-45.2-6.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "MozillaThunderbird-45.2-6.1.x86_64", "product": { "name": "MozillaThunderbird-45.2-6.1.x86_64", "product_id": "MozillaThunderbird-45.2-6.1.x86_64" } }, { "category": "product_version", "name": "MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "product": { "name": "MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "product_id": "MozillaThunderbird-buildsymbols-45.2-6.1.x86_64" } }, { "category": "product_version", "name": "MozillaThunderbird-devel-45.2-6.1.x86_64", "product": { "name": "MozillaThunderbird-devel-45.2-6.1.x86_64", "product_id": "MozillaThunderbird-devel-45.2-6.1.x86_64" } }, { "category": "product_version", "name": "MozillaThunderbird-translations-common-45.2-6.1.x86_64", "product": { "name": "MozillaThunderbird-translations-common-45.2-6.1.x86_64", "product_id": "MozillaThunderbird-translations-common-45.2-6.1.x86_64" } }, { "category": "product_version", "name": "MozillaThunderbird-translations-other-45.2-6.1.x86_64", "product": { "name": "MozillaThunderbird-translations-other-45.2-6.1.x86_64", "product_id": "MozillaThunderbird-translations-other-45.2-6.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Package Hub 12", "product": { "name": "SUSE Package Hub 12", "product_id": "SUSE Package Hub 12", "product_identification_helper": { "cpe": "cpe:/o:suse:packagehub:12" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-45.2-6.1.aarch64 as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64" }, "product_reference": "MozillaThunderbird-45.2-6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-45.2-6.1.s390x as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x" }, "product_reference": "MozillaThunderbird-45.2-6.1.s390x", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-45.2-6.1.x86_64 as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64" }, "product_reference": "MozillaThunderbird-45.2-6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-buildsymbols-45.2-6.1.x86_64 as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64" }, "product_reference": "MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-devel-45.2-6.1.aarch64 as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64" }, "product_reference": "MozillaThunderbird-devel-45.2-6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-devel-45.2-6.1.s390x as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x" }, "product_reference": "MozillaThunderbird-devel-45.2-6.1.s390x", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-devel-45.2-6.1.x86_64 as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64" }, "product_reference": "MozillaThunderbird-devel-45.2-6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-translations-common-45.2-6.1.aarch64 as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64" }, "product_reference": "MozillaThunderbird-translations-common-45.2-6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-translations-common-45.2-6.1.s390x as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x" }, "product_reference": "MozillaThunderbird-translations-common-45.2-6.1.s390x", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-translations-common-45.2-6.1.x86_64 as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64" }, "product_reference": "MozillaThunderbird-translations-common-45.2-6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-translations-other-45.2-6.1.aarch64 as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64" }, "product_reference": "MozillaThunderbird-translations-other-45.2-6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-translations-other-45.2-6.1.s390x as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x" }, "product_reference": "MozillaThunderbird-translations-other-45.2-6.1.s390x", "relates_to_product_reference": "SUSE Package Hub 12" }, { "category": "default_component_of", "full_product_name": { "name": "MozillaThunderbird-translations-other-45.2-6.1.x86_64 as component of SUSE Package Hub 12", "product_id": "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" }, "product_reference": "MozillaThunderbird-translations-other-45.2-6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 12" } ] }, "vulnerabilities": [ { "cve": "CVE-2016-1952", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1952" } ], "notes": [ { "category": "general", "text": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1952", "url": "https://www.suse.com/security/cve/CVE-2016-1952" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1952", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1952" }, { "cve": "CVE-2016-1953", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1953" } ], "notes": [ { "category": "general", "text": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1953", "url": "https://www.suse.com/security/cve/CVE-2016-1953" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1953", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1953" }, { "cve": "CVE-2016-1954", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1954" } ], "notes": [ { "category": "general", "text": "The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a URL of a local file.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1954", "url": "https://www.suse.com/security/cve/CVE-2016-1954" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1954", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1954" }, { "cve": "CVE-2016-1955", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1955" } ], "notes": [ { "category": "general", "text": "Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1955", "url": "https://www.suse.com/security/cve/CVE-2016-1955" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1955", "url": "https://bugzilla.suse.com/969894" }, { "category": "external", "summary": "SUSE Bug 970257 for CVE-2016-1955", "url": "https://bugzilla.suse.com/970257" }, { "category": "external", "summary": "SUSE Bug 970377 for CVE-2016-1955", "url": "https://bugzilla.suse.com/970377" }, { "category": "external", "summary": "SUSE Bug 970378 for CVE-2016-1955", "url": "https://bugzilla.suse.com/970378" }, { "category": "external", "summary": "SUSE Bug 970379 for CVE-2016-1955", "url": "https://bugzilla.suse.com/970379" }, { "category": "external", "summary": "SUSE Bug 970380 for CVE-2016-1955", "url": "https://bugzilla.suse.com/970380" }, { "category": "external", "summary": "SUSE Bug 970381 for CVE-2016-1955", "url": "https://bugzilla.suse.com/970381" }, { "category": "external", "summary": "SUSE Bug 970431 for CVE-2016-1955", "url": "https://bugzilla.suse.com/970431" }, { "category": "external", "summary": "SUSE Bug 970433 for CVE-2016-1955", "url": "https://bugzilla.suse.com/970433" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1955" }, { "cve": "CVE-2016-1956", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1956" } ], "notes": [ { "category": "general", "text": "Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1956", "url": "https://www.suse.com/security/cve/CVE-2016-1956" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1956", "url": "https://bugzilla.suse.com/969894" }, { "category": "external", "summary": "SUSE Bug 970257 for CVE-2016-1956", "url": "https://bugzilla.suse.com/970257" }, { "category": "external", "summary": "SUSE Bug 970377 for CVE-2016-1956", "url": "https://bugzilla.suse.com/970377" }, { "category": "external", "summary": "SUSE Bug 970378 for CVE-2016-1956", "url": "https://bugzilla.suse.com/970378" }, { "category": "external", "summary": "SUSE Bug 970379 for CVE-2016-1956", "url": "https://bugzilla.suse.com/970379" }, { "category": "external", "summary": "SUSE Bug 970380 for CVE-2016-1956", "url": "https://bugzilla.suse.com/970380" }, { "category": "external", "summary": "SUSE Bug 970381 for CVE-2016-1956", "url": "https://bugzilla.suse.com/970381" }, { "category": "external", "summary": "SUSE Bug 970431 for CVE-2016-1956", "url": "https://bugzilla.suse.com/970431" }, { "category": "external", "summary": "SUSE Bug 970433 for CVE-2016-1956", "url": "https://bugzilla.suse.com/970433" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1956" }, { "cve": "CVE-2016-1957", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1957" } ], "notes": [ { "category": "general", "text": "Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1957", "url": "https://www.suse.com/security/cve/CVE-2016-1957" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1957", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 4.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "moderate" } ], "title": "CVE-2016-1957" }, { "cve": "CVE-2016-1960", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1960" } ], "notes": [ { "category": "general", "text": "Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1960", "url": "https://www.suse.com/security/cve/CVE-2016-1960" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1960", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1960" }, { "cve": "CVE-2016-1961", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1961" } ], "notes": [ { "category": "general", "text": "Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1961", "url": "https://www.suse.com/security/cve/CVE-2016-1961" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1961", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1961" }, { "cve": "CVE-2016-1964", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1964" } ], "notes": [ { "category": "general", "text": "Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1964", "url": "https://www.suse.com/security/cve/CVE-2016-1964" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1964", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1964" }, { "cve": "CVE-2016-1974", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1974" } ], "notes": [ { "category": "general", "text": "The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1974", "url": "https://www.suse.com/security/cve/CVE-2016-1974" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1974", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1974" }, { "cve": "CVE-2016-1977", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-1977" } ], "notes": [ { "category": "general", "text": "The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-1977", "url": "https://www.suse.com/security/cve/CVE-2016-1977" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-1977", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-1977" }, { "cve": "CVE-2016-2790", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2790" } ], "notes": [ { "category": "general", "text": "The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2790", "url": "https://www.suse.com/security/cve/CVE-2016-2790" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2790", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2790" }, { "cve": "CVE-2016-2791", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2791" } ], "notes": [ { "category": "general", "text": "The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2791", "url": "https://www.suse.com/security/cve/CVE-2016-2791" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2791", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2791" }, { "cve": "CVE-2016-2792", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2792" } ], "notes": [ { "category": "general", "text": "The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2800.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2792", "url": "https://www.suse.com/security/cve/CVE-2016-2792" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2792", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2792" }, { "cve": "CVE-2016-2793", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2793" } ], "notes": [ { "category": "general", "text": "CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2793", "url": "https://www.suse.com/security/cve/CVE-2016-2793" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2793", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2793" }, { "cve": "CVE-2016-2794", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2794" } ], "notes": [ { "category": "general", "text": "The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2794", "url": "https://www.suse.com/security/cve/CVE-2016-2794" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2794", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "critical" } ], "title": "CVE-2016-2794" }, { "cve": "CVE-2016-2795", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2795" } ], "notes": [ { "category": "general", "text": "The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2795", "url": "https://www.suse.com/security/cve/CVE-2016-2795" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2795", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2795" }, { "cve": "CVE-2016-2796", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2796" } ], "notes": [ { "category": "general", "text": "Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2796", "url": "https://www.suse.com/security/cve/CVE-2016-2796" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2796", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2796" }, { "cve": "CVE-2016-2797", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2797" } ], "notes": [ { "category": "general", "text": "The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2797", "url": "https://www.suse.com/security/cve/CVE-2016-2797" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2797", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2797" }, { "cve": "CVE-2016-2798", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2798" } ], "notes": [ { "category": "general", "text": "The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2798", "url": "https://www.suse.com/security/cve/CVE-2016-2798" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2798", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2798" }, { "cve": "CVE-2016-2799", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2799" } ], "notes": [ { "category": "general", "text": "Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2799", "url": "https://www.suse.com/security/cve/CVE-2016-2799" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2799", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "critical" } ], "title": "CVE-2016-2799" }, { "cve": "CVE-2016-2800", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2800" } ], "notes": [ { "category": "general", "text": "The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2792.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2800", "url": "https://www.suse.com/security/cve/CVE-2016-2800" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2800", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2800" }, { "cve": "CVE-2016-2801", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2801" } ], "notes": [ { "category": "general", "text": "The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2797.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2801", "url": "https://www.suse.com/security/cve/CVE-2016-2801" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2801", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2801" }, { "cve": "CVE-2016-2802", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2802" } ], "notes": [ { "category": "general", "text": "The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2802", "url": "https://www.suse.com/security/cve/CVE-2016-2802" }, { "category": "external", "summary": "SUSE Bug 969894 for CVE-2016-2802", "url": "https://bugzilla.suse.com/969894" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "important" } ], "title": "CVE-2016-2802" }, { "cve": "CVE-2016-2806", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2806" } ], "notes": [ { "category": "general", "text": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2806", "url": "https://www.suse.com/security/cve/CVE-2016-2806" }, { "category": "external", "summary": "SUSE Bug 977375 for CVE-2016-2806", "url": "https://bugzilla.suse.com/977375" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "moderate" } ], "title": "CVE-2016-2806" }, { "cve": "CVE-2016-2807", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2807" } ], "notes": [ { "category": "general", "text": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2807", "url": "https://www.suse.com/security/cve/CVE-2016-2807" }, { "category": "external", "summary": "SUSE Bug 977333 for CVE-2016-2807", "url": "https://bugzilla.suse.com/977333" }, { "category": "external", "summary": "SUSE Bug 977376 for CVE-2016-2807", "url": "https://bugzilla.suse.com/977376" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "moderate" } ], "title": "CVE-2016-2807" }, { "cve": "CVE-2016-2815", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2815" } ], "notes": [ { "category": "general", "text": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2815", "url": "https://www.suse.com/security/cve/CVE-2016-2815" }, { "category": "external", "summary": "SUSE Bug 983549 for CVE-2016-2815", "url": "https://bugzilla.suse.com/983549" }, { "category": "external", "summary": "SUSE Bug 983638 for CVE-2016-2815", "url": "https://bugzilla.suse.com/983638" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "moderate" } ], "title": "CVE-2016-2815" }, { "cve": "CVE-2016-2818", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2016-2818" } ], "notes": [ { "category": "general", "text": "Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2016-2818", "url": "https://www.suse.com/security/cve/CVE-2016-2818" }, { "category": "external", "summary": "SUSE Bug 983549 for CVE-2016-2818", "url": "https://bugzilla.suse.com/983549" }, { "category": "external", "summary": "SUSE Bug 983638 for CVE-2016-2818", "url": "https://bugzilla.suse.com/983638" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1.x86_64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.aarch64", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.s390x", "SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2016-07-10T18:30:29Z", "details": "moderate" } ], "title": "CVE-2016-2818" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…