{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"moderate"},"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"MozillaFirefox-98.0-1.1 on GA media","title":"Title of the patch"},{"category":"description","text":"These are all security issues fixed in the MozillaFirefox-98.0-1.1 package on the GA media of openSUSE Tumbleweed.","title":"Description of the patch"},{"category":"details","text":"openSUSE-Tumbleweed-2024-11908","title":"Patchnames"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"SUSE ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"self","summary":"URL of this CSAF notice","url":"https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_11908-1.json"},{"category":"self","summary":"SUSE CVE CVE-2022-0843 page","url":"https://www.suse.com/security/cve/CVE-2022-0843/"},{"category":"self","summary":"SUSE CVE CVE-2022-26381 page","url":"https://www.suse.com/security/cve/CVE-2022-26381/"},{"category":"self","summary":"SUSE CVE CVE-2022-26382 page","url":"https://www.suse.com/security/cve/CVE-2022-26382/"},{"category":"self","summary":"SUSE CVE CVE-2022-26383 page","url":"https://www.suse.com/security/cve/CVE-2022-26383/"},{"category":"self","summary":"SUSE CVE CVE-2022-26384 page","url":"https://www.suse.com/security/cve/CVE-2022-26384/"},{"category":"self","summary":"SUSE CVE CVE-2022-26385 page","url":"https://www.suse.com/security/cve/CVE-2022-26385/"},{"category":"self","summary":"SUSE CVE CVE-2022-26387 page","url":"https://www.suse.com/security/cve/CVE-2022-26387/"}],"title":"MozillaFirefox-98.0-1.1 on GA media","tracking":{"current_release_date":"2024-06-15T00:00:00Z","generator":{"date":"2024-06-15T00:00:00Z","engine":{"name":"cve-database.git:bin/generate-csaf.pl","version":"1"}},"id":"openSUSE-SU-2024:11908-1","initial_release_date":"2024-06-15T00:00:00Z","revision_history":[{"date":"2024-06-15T00:00:00Z","number":"1","summary":"Current version"}],"status":"final","version":"1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_version","name":"MozillaFirefox-98.0-1.1.aarch64","product":{"name":"MozillaFirefox-98.0-1.1.aarch64","product_id":"MozillaFirefox-98.0-1.1.aarch64"}},{"category":"product_version","name":"MozillaFirefox-branding-upstream-98.0-1.1.aarch64","product":{"name":"MozillaFirefox-branding-upstream-98.0-1.1.aarch64","product_id":"MozillaFirefox-branding-upstream-98.0-1.1.aarch64"}},{"category":"product_version","name":"MozillaFirefox-devel-98.0-1.1.aarch64","product":{"name":"MozillaFirefox-devel-98.0-1.1.aarch64","product_id":"MozillaFirefox-devel-98.0-1.1.aarch64"}},{"category":"product_version","name":"MozillaFirefox-translations-common-98.0-1.1.aarch64","product":{"name":"MozillaFirefox-translations-common-98.0-1.1.aarch64","product_id":"MozillaFirefox-translations-common-98.0-1.1.aarch64"}},{"category":"product_version","name":"MozillaFirefox-translations-other-98.0-1.1.aarch64","product":{"name":"MozillaFirefox-translations-other-98.0-1.1.aarch64","product_id":"MozillaFirefox-translations-other-98.0-1.1.aarch64"}}],"category":"architecture","name":"aarch64"},{"branches":[{"category":"product_version","name":"MozillaFirefox-98.0-1.1.ppc64le","product":{"name":"MozillaFirefox-98.0-1.1.ppc64le","product_id":"MozillaFirefox-98.0-1.1.ppc64le"}},{"category":"product_version","name":"MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","product":{"name":"MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","product_id":"MozillaFirefox-branding-upstream-98.0-1.1.ppc64le"}},{"category":"product_version","name":"MozillaFirefox-devel-98.0-1.1.ppc64le","product":{"name":"MozillaFirefox-devel-98.0-1.1.ppc64le","product_id":"MozillaFirefox-devel-98.0-1.1.ppc64le"}},{"category":"product_version","name":"MozillaFirefox-translations-common-98.0-1.1.ppc64le","product":{"name":"MozillaFirefox-translations-common-98.0-1.1.ppc64le","product_id":"MozillaFirefox-translations-common-98.0-1.1.ppc64le"}},{"category":"product_version","name":"MozillaFirefox-translations-other-98.0-1.1.ppc64le","product":{"name":"MozillaFirefox-translations-other-98.0-1.1.ppc64le","product_id":"MozillaFirefox-translations-other-98.0-1.1.ppc64le"}}],"category":"architecture","name":"ppc64le"},{"branches":[{"category":"product_version","name":"MozillaFirefox-98.0-1.1.s390x","product":{"name":"MozillaFirefox-98.0-1.1.s390x","product_id":"MozillaFirefox-98.0-1.1.s390x"}},{"category":"product_version","name":"MozillaFirefox-branding-upstream-98.0-1.1.s390x","product":{"name":"MozillaFirefox-branding-upstream-98.0-1.1.s390x","product_id":"MozillaFirefox-branding-upstream-98.0-1.1.s390x"}},{"category":"product_version","name":"MozillaFirefox-devel-98.0-1.1.s390x","product":{"name":"MozillaFirefox-devel-98.0-1.1.s390x","product_id":"MozillaFirefox-devel-98.0-1.1.s390x"}},{"category":"product_version","name":"MozillaFirefox-translations-common-98.0-1.1.s390x","product":{"name":"MozillaFirefox-translations-common-98.0-1.1.s390x","product_id":"MozillaFirefox-translations-common-98.0-1.1.s390x"}},{"category":"product_version","name":"MozillaFirefox-translations-other-98.0-1.1.s390x","product":{"name":"MozillaFirefox-translations-other-98.0-1.1.s390x","product_id":"MozillaFirefox-translations-other-98.0-1.1.s390x"}}],"category":"architecture","name":"s390x"},{"branches":[{"category":"product_version","name":"MozillaFirefox-98.0-1.1.x86_64","product":{"name":"MozillaFirefox-98.0-1.1.x86_64","product_id":"MozillaFirefox-98.0-1.1.x86_64"}},{"category":"product_version","name":"MozillaFirefox-branding-upstream-98.0-1.1.x86_64","product":{"name":"MozillaFirefox-branding-upstream-98.0-1.1.x86_64","product_id":"MozillaFirefox-branding-upstream-98.0-1.1.x86_64"}},{"category":"product_version","name":"MozillaFirefox-devel-98.0-1.1.x86_64","product":{"name":"MozillaFirefox-devel-98.0-1.1.x86_64","product_id":"MozillaFirefox-devel-98.0-1.1.x86_64"}},{"category":"product_version","name":"MozillaFirefox-translations-common-98.0-1.1.x86_64","product":{"name":"MozillaFirefox-translations-common-98.0-1.1.x86_64","product_id":"MozillaFirefox-translations-common-98.0-1.1.x86_64"}},{"category":"product_version","name":"MozillaFirefox-translations-other-98.0-1.1.x86_64","product":{"name":"MozillaFirefox-translations-other-98.0-1.1.x86_64","product_id":"MozillaFirefox-translations-other-98.0-1.1.x86_64"}}],"category":"architecture","name":"x86_64"},{"branches":[{"category":"product_name","name":"openSUSE Tumbleweed","product":{"name":"openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed","product_identification_helper":{"cpe":"cpe:/o:opensuse:tumbleweed"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-98.0-1.1.aarch64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64"},"product_reference":"MozillaFirefox-98.0-1.1.aarch64","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-98.0-1.1.ppc64le as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le"},"product_reference":"MozillaFirefox-98.0-1.1.ppc64le","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-98.0-1.1.s390x as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x"},"product_reference":"MozillaFirefox-98.0-1.1.s390x","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-98.0-1.1.x86_64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64"},"product_reference":"MozillaFirefox-98.0-1.1.x86_64","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-branding-upstream-98.0-1.1.aarch64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64"},"product_reference":"MozillaFirefox-branding-upstream-98.0-1.1.aarch64","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-branding-upstream-98.0-1.1.ppc64le as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le"},"product_reference":"MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-branding-upstream-98.0-1.1.s390x as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x"},"product_reference":"MozillaFirefox-branding-upstream-98.0-1.1.s390x","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-branding-upstream-98.0-1.1.x86_64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64"},"product_reference":"MozillaFirefox-branding-upstream-98.0-1.1.x86_64","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-devel-98.0-1.1.aarch64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64"},"product_reference":"MozillaFirefox-devel-98.0-1.1.aarch64","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-devel-98.0-1.1.ppc64le as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le"},"product_reference":"MozillaFirefox-devel-98.0-1.1.ppc64le","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-devel-98.0-1.1.s390x as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x"},"product_reference":"MozillaFirefox-devel-98.0-1.1.s390x","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-devel-98.0-1.1.x86_64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64"},"product_reference":"MozillaFirefox-devel-98.0-1.1.x86_64","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-translations-common-98.0-1.1.aarch64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64"},"product_reference":"MozillaFirefox-translations-common-98.0-1.1.aarch64","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-translations-common-98.0-1.1.ppc64le as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le"},"product_reference":"MozillaFirefox-translations-common-98.0-1.1.ppc64le","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-translations-common-98.0-1.1.s390x as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x"},"product_reference":"MozillaFirefox-translations-common-98.0-1.1.s390x","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-translations-common-98.0-1.1.x86_64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64"},"product_reference":"MozillaFirefox-translations-common-98.0-1.1.x86_64","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-translations-other-98.0-1.1.aarch64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64"},"product_reference":"MozillaFirefox-translations-other-98.0-1.1.aarch64","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-translations-other-98.0-1.1.ppc64le as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le"},"product_reference":"MozillaFirefox-translations-other-98.0-1.1.ppc64le","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-translations-other-98.0-1.1.s390x as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x"},"product_reference":"MozillaFirefox-translations-other-98.0-1.1.s390x","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"MozillaFirefox-translations-other-98.0-1.1.x86_64 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"},"product_reference":"MozillaFirefox-translations-other-98.0-1.1.x86_64","relates_to_product_reference":"openSUSE Tumbleweed"}]},"vulnerabilities":[{"cve":"CVE-2022-0843","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2022-0843"}],"notes":[{"category":"general","text":"Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 98.","title":"CVE description"}],"product_status":{"recommended":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]},"references":[{"category":"external","summary":"CVE-2022-0843","url":"https://www.suse.com/security/cve/CVE-2022-0843"},{"category":"external","summary":"SUSE Bug 1196900 for CVE-2022-0843","url":"https://bugzilla.suse.com/1196900"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"threats":[{"category":"impact","date":"2024-06-15T00:00:00Z","details":"critical"}],"title":"CVE-2022-0843"},{"cve":"CVE-2022-26381","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2022-26381"}],"notes":[{"category":"general","text":"An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.","title":"CVE description"}],"product_status":{"recommended":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]},"references":[{"category":"external","summary":"CVE-2022-26381","url":"https://www.suse.com/security/cve/CVE-2022-26381"},{"category":"external","summary":"SUSE Bug 1196900 for CVE-2022-26381","url":"https://bugzilla.suse.com/1196900"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"scores":[{"cvss_v3":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"threats":[{"category":"impact","date":"2024-06-15T00:00:00Z","details":"critical"}],"title":"CVE-2022-26381"},{"cve":"CVE-2022-26382","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2022-26382"}],"notes":[{"category":"general","text":"While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.","title":"CVE description"}],"product_status":{"recommended":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]},"references":[{"category":"external","summary":"CVE-2022-26382","url":"https://www.suse.com/security/cve/CVE-2022-26382"},{"category":"external","summary":"SUSE Bug 1196900 for CVE-2022-26382","url":"https://bugzilla.suse.com/1196900"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","version":"3.1"},"products":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"threats":[{"category":"impact","date":"2024-06-15T00:00:00Z","details":"critical"}],"title":"CVE-2022-26382"},{"cve":"CVE-2022-26383","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2022-26383"}],"notes":[{"category":"general","text":"When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.","title":"CVE description"}],"product_status":{"recommended":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]},"references":[{"category":"external","summary":"CVE-2022-26383","url":"https://www.suse.com/security/cve/CVE-2022-26383"},{"category":"external","summary":"SUSE Bug 1196900 for CVE-2022-26383","url":"https://bugzilla.suse.com/1196900"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"scores":[{"cvss_v3":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","version":"3.1"},"products":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"threats":[{"category":"impact","date":"2024-06-15T00:00:00Z","details":"critical"}],"title":"CVE-2022-26383"},{"cve":"CVE-2022-26384","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2022-26384"}],"notes":[{"category":"general","text":"If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.","title":"CVE description"}],"product_status":{"recommended":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]},"references":[{"category":"external","summary":"CVE-2022-26384","url":"https://www.suse.com/security/cve/CVE-2022-26384"},{"category":"external","summary":"SUSE Bug 1196900 for CVE-2022-26384","url":"https://bugzilla.suse.com/1196900"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"scores":[{"cvss_v3":{"baseScore":9.6,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","version":"3.1"},"products":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"threats":[{"category":"impact","date":"2024-06-15T00:00:00Z","details":"critical"}],"title":"CVE-2022-26384"},{"cve":"CVE-2022-26385","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2022-26385"}],"notes":[{"category":"general","text":"In unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 98.","title":"CVE description"}],"product_status":{"recommended":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]},"references":[{"category":"external","summary":"CVE-2022-26385","url":"https://www.suse.com/security/cve/CVE-2022-26385"},{"category":"external","summary":"SUSE Bug 1196900 for CVE-2022-26385","url":"https://bugzilla.suse.com/1196900"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"scores":[{"cvss_v3":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"products":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"threats":[{"category":"impact","date":"2024-06-15T00:00:00Z","details":"critical"}],"title":"CVE-2022-26385"},{"cve":"CVE-2022-26387","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2022-26387"}],"notes":[{"category":"general","text":"When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.","title":"CVE description"}],"product_status":{"recommended":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]},"references":[{"category":"external","summary":"CVE-2022-26387","url":"https://www.suse.com/security/cve/CVE-2022-26387"},{"category":"external","summary":"SUSE Bug 1196900 for CVE-2022-26387","url":"https://bugzilla.suse.com/1196900"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"products":["openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-branding-upstream-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-devel-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-common-98.0-1.1.x86_64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.aarch64","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.ppc64le","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.s390x","openSUSE Tumbleweed:MozillaFirefox-translations-other-98.0-1.1.x86_64"]}],"threats":[{"category":"impact","date":"2024-06-15T00:00:00Z","details":"critical"}],"title":"CVE-2022-26387"}]}