SUSE-SU-2016:2061-1
Vulnerability from csaf_suse - Published: 2016-08-12 16:10 - Updated: 2026-09-20 12:16Summary
Security update for MozillaFirefox, MozillaFirefox-branding-SLED, mozilla-nspr and mozilla-nss
Severity
Important
Notes
Title of the patch: Security update for MozillaFirefox, MozillaFirefox-branding-SLED, mozilla-nspr and mozilla-nss
Description of the patch: MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr and mozilla-nss were updated to fix nine security issues.
MozillaFirefox was updated to version 45.3.0 ESR. mozilla-nss was updated to version 3.21.1, mozilla-nspr to version 4.12.
These security issues were fixed in 45.3.0ESR:
- CVE-2016-2835/CVE-2016-2836: Miscellaneous memory safety hazards (rv:48.0 / rv:45.3) (MFSA 2016-62)
- CVE-2016-2830: Favicon network connection can persist when page is closed (MFSA 2016-63)
- CVE-2016-2838: Buffer overflow rendering SVG with bidirectional content (MFSA 2016-64)
- CVE-2016-2839: Cairo rendering crash due to memory allocation issue with FFmpeg 0.10 (MFSA 2016-65)
- CVE-2016-5252: Stack underflow during 2D graphics rendering (MFSA 2016-67)
- CVE-2016-5254: Use-after-free when using alt key and toplevel menus (MFSA 2016-70)
- CVE-2016-5258: Use-after-free in DTLS during WebRTC session shutdown (MFSA 2016-72)
- CVE-2016-5259: Use-after-free in service workers with nested sync events (MFSA 2016-73)
- CVE-2016-5262: Scripts on marquee tag can execute in sandboxed iframes (MFSA 2016-76)
- CVE-2016-2837: Buffer overflow in ClearKey Content Decryption Module (CDM) during video playback (MFSA 2016-77)
- CVE-2016-5263: Type confusion in display transformation (MFSA 2016-78)
- CVE-2016-5264: Use-after-free when applying SVG effects (MFSA 2016-79)
- CVE-2016-5265: Same-origin policy violation using local HTML file and saved shortcut file (MFSA 2016-80)
- CVE-2016-6354: Fix for possible buffer overrun (bsc#990856)
Security issues fixed in 45.2.0.ESR:
- CVE-2016-2834: Memory safety bugs in NSS (MFSA 2016-61) (bsc#983639).
- CVE-2016-2824: Out-of-bounds write with WebGL shader (MFSA 2016-53) (bsc#983651).
- CVE-2016-2822: Addressbar spoofing though the SELECT element (MFSA 2016-52) (bsc#983652).
- CVE-2016-2821: Use-after-free deleting tables from a contenteditable document (MFSA 2016-51) (bsc#983653).
- CVE-2016-2819: Buffer overflow parsing HTML5 fragments (MFSA 2016-50) (bsc#983655).
- CVE-2016-2828: Use-after-free when textures are used in WebGL operations after recycle pool destruction (MFSA 2016-56) (bsc#983646).
- CVE-2016-2831: Entering fullscreen and persistent pointerlock without user permission (MFSA 2016-58) (bsc#983643).
- CVE-2016-2815, CVE-2016-2818: Miscellaneous memory safety hazards (MFSA 2016-49) (bsc#983638)
These non-security issues were fixed:
- Fix crashes on aarch64
* Determine page size at runtime (bsc#984006)
* Allow aarch64 to work in safe mode (bsc#985659)
- Fix crashes on mainframes
- Temporarily bind Firefox to the first CPU as a hotfix
for an apparent race condition (bsc#989196, bsc#990628)
All extensions must now be signed by addons.mozilla.org. Please read README.SUSE for more details.
Patchnames: slessp2-MozillaFirefox-12690
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
8.8 (High)
Affected products
Recommended
144 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:MozillaFirefox-0:45.3.0esr-48.1.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:MozillaFirefox-0:45.3.0esr-48.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:MozillaFirefox-0:45.3.0esr-48.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:MozillaFirefox-branding-SLED-0:45.0-20.38.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:MozillaFirefox-branding-SLED-0:45.0-20.38.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:MozillaFirefox-branding-SLED-0:45.0-20.38.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:MozillaFirefox-translations-0:45.3.0esr-48.1.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:MozillaFirefox-translations-0:45.3.0esr-48.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:MozillaFirefox-translations-0:45.3.0esr-48.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:firefox-fontconfig-0:2.11.0-4.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:firefox-fontconfig-0:2.11.0-4.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:firefox-fontconfig-0:2.11.0-4.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:libfreebl3-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:libfreebl3-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:libfreebl3-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:libfreebl3-32bit-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:libfreebl3-32bit-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nspr-0:4.12-25.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nspr-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nspr-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nspr-32bit-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nspr-32bit-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nspr-devel-0:4.12-25.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nspr-devel-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nspr-devel-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-32bit-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-32bit-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-devel-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-devel-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-devel-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-tools-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-tools-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise High Performance Computing 11 SP2:mozilla-nss-tools-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:MozillaFirefox-0:45.3.0esr-48.1.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:MozillaFirefox-0:45.3.0esr-48.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:MozillaFirefox-0:45.3.0esr-48.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:MozillaFirefox-branding-SLED-0:45.0-20.38.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:MozillaFirefox-branding-SLED-0:45.0-20.38.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:MozillaFirefox-branding-SLED-0:45.0-20.38.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:MozillaFirefox-translations-0:45.3.0esr-48.1.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:MozillaFirefox-translations-0:45.3.0esr-48.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:MozillaFirefox-translations-0:45.3.0esr-48.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:firefox-fontconfig-0:2.11.0-4.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:firefox-fontconfig-0:2.11.0-4.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:firefox-fontconfig-0:2.11.0-4.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:libfreebl3-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:libfreebl3-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:libfreebl3-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:libfreebl3-32bit-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:libfreebl3-32bit-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nspr-0:4.12-25.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nspr-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nspr-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nspr-32bit-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nspr-32bit-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nspr-devel-0:4.12-25.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nspr-devel-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nspr-devel-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-32bit-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-32bit-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-devel-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-devel-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-devel-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-tools-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-tools-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2-LTSS:mozilla-nss-tools-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:MozillaFirefox-0:45.3.0esr-48.1.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:MozillaFirefox-0:45.3.0esr-48.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:MozillaFirefox-0:45.3.0esr-48.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:MozillaFirefox-branding-SLED-0:45.0-20.38.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:MozillaFirefox-branding-SLED-0:45.0-20.38.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:MozillaFirefox-branding-SLED-0:45.0-20.38.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:MozillaFirefox-translations-0:45.3.0esr-48.1.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:MozillaFirefox-translations-0:45.3.0esr-48.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:MozillaFirefox-translations-0:45.3.0esr-48.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:firefox-fontconfig-0:2.11.0-4.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:firefox-fontconfig-0:2.11.0-4.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:firefox-fontconfig-0:2.11.0-4.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:libfreebl3-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:libfreebl3-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:libfreebl3-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:libfreebl3-32bit-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:libfreebl3-32bit-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nspr-0:4.12-25.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nspr-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nspr-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nspr-32bit-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nspr-32bit-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nspr-devel-0:4.12-25.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nspr-devel-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nspr-devel-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-32bit-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-32bit-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-devel-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-devel-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-devel-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-tools-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-tools-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server 11 SP2:mozilla-nss-tools-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:MozillaFirefox-0:45.3.0esr-48.1.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:MozillaFirefox-0:45.3.0esr-48.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:MozillaFirefox-0:45.3.0esr-48.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:MozillaFirefox-branding-SLED-0:45.0-20.38.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:MozillaFirefox-branding-SLED-0:45.0-20.38.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:MozillaFirefox-branding-SLED-0:45.0-20.38.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:MozillaFirefox-translations-0:45.3.0esr-48.1.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:MozillaFirefox-translations-0:45.3.0esr-48.1.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:MozillaFirefox-translations-0:45.3.0esr-48.1.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:firefox-fontconfig-0:2.11.0-4.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:firefox-fontconfig-0:2.11.0-4.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:firefox-fontconfig-0:2.11.0-4.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:libfreebl3-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:libfreebl3-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:libfreebl3-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:libfreebl3-32bit-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:libfreebl3-32bit-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nspr-0:4.12-25.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nspr-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nspr-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nspr-32bit-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nspr-32bit-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nspr-devel-0:4.12-25.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nspr-devel-0:4.12-25.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nspr-devel-0:4.12-25.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-32bit-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-32bit-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-devel-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-devel-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-devel-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-tools-0:3.21.1-26.2.i586 | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-tools-0:3.21.1-26.2.s390x | — |
Vendor Fix
|
|
| Unresolved product id: SUSE Linux Enterprise Server for SAP Applications 11 SP2:mozilla-nss-tools-0:3.21.1-26.2.x86_64 | — |
Vendor Fix
|
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
7.5 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
6.5 (Medium)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
4.3 (Medium)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
6.3 (Medium)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
6.5 (Medium)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
9.8 (Critical)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
6.1 (Medium)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
8.8 (High)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
5.5 (Medium)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
moderate
9.8 (Critical)
Affected products
Recommended
144 products, the same list as for
CVE-2016-2815
Threats
Impact
low
References
105 references
Loading 1.1 MB of JSON…
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…