8.8 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
by @LeSuisse Activity log
- Created suggestion
-
@jopejoe1
ignored
11 packages
- firefoxpwa
- faust2firefox
- firefox_decrypt
- firefox-gnome-theme
- firefox-sync-client
- pkgsRocm.firefoxpwa
- gnomeExtensions.firefox-profiles
- roundcubePlugins.thunderbird_labels
- gnomeExtensions.firefox-pip-always-on-top
- gnomeExtensions.pip-alwaysontop-for-firefox
- vscode-extensions.firefox-devtools.vscode-firefox-debug
-
@LeSuisse
ignored
17 packages
- thunderbirdPackages.thunderbird-128
- pkgsRocm.firefox
- pkgsRocm.thunderbird
- pkgsRocm.firefox-beta
- pkgsRocm.thunderbird-unwrapped
- firefox-devedition-unwrapped
- pkgsRocm.firefox-devedition
- pkgsRocm.firefox-unwrapped
- pkgsRocm.thunderbird-latest
- pkgsRocm.thunderbird-latest-unwrapped
- pkgsRocm.firefox-devedition-unwrapped
- pkgsRocm.thunderbirdPackages.thunderbird
- pkgsRocm.thunderbirdPackages.thunderbird-latest
- thunderbird-128-unwrapped
- pkgsRocm.firefox-mobile
- pkgsRocm.firefox-beta-unwrapped
- firefox-beta-unwrapped
-
@LeSuisse
deleted
maintainer.delete
4 maintainers
- @nbp
- @vcunat
- @mweinelt
- @lovesegfault
- @LeSuisse accepted
- @LeSuisse published on GitHub
Heap buffer overflow in libvpx
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.
References
Affected products
- <147.0.4
- <140.7.1
- <115.32.1
- <140.7.2
- <147.0.2
Matching in nixpkgs
pkgs.firefox-unwrapped
Web browser built from Firefox source tree
pkgs.firefox-esr-unwrapped
Web browser built from Firefox source tree
-
nixos-unstable 140.7.0esr
- nixpkgs-unstable 140.7.0esr
- nixos-unstable-small 140.7.0esr
-
nixos-25.11 140.7.0esr
- nixos-25.11-small 140.7.0esr
- nixpkgs-25.11-darwin 140.7.0esr
pkgs.thunderbird-unwrapped
Full-featured e-mail client
pkgs.firefox-esr-140-unwrapped
Web browser built from Firefox source tree
-
nixos-unstable 140.7.0esr
- nixpkgs-unstable 140.7.0esr
- nixos-unstable-small 140.7.0esr
-
nixos-25.11 140.7.0esr
- nixos-25.11-small 140.7.0esr
- nixpkgs-25.11-darwin 140.7.0esr
pkgs.thunderbird-140-unwrapped
Full-featured e-mail client
-
nixos-unstable 140.7.0esr
- nixpkgs-unstable 140.7.0esr
- nixos-unstable-small 140.7.0esr
-
nixos-25.11 140.7.0esr
- nixos-25.11-small 140.7.0esr
- nixpkgs-25.11-darwin 140.7.0esr
pkgs.thunderbird-esr-unwrapped
Full-featured e-mail client
-
nixos-unstable 140.7.0esr
- nixpkgs-unstable 140.7.0esr
- nixos-unstable-small 140.7.0esr
-
nixos-25.11 140.7.0esr
- nixos-25.11-small 140.7.0esr
- nixpkgs-25.11-darwin 140.7.0esr
pkgs.thunderbird-latest-unwrapped
Full-featured e-mail client
pkgs.thunderbirdPackages.thunderbird
Full-featured e-mail client
pkgs.thunderbirdPackages.thunderbird-140
Full-featured e-mail client
-
nixos-unstable 140.7.0esr
- nixpkgs-unstable 140.7.0esr
- nixos-unstable-small 140.7.0esr
-
nixos-25.11 140.7.0esr
- nixos-25.11-small 140.7.0esr
- nixpkgs-25.11-darwin 140.7.0esr
pkgs.thunderbirdPackages.thunderbird-esr
Full-featured e-mail client
-
nixos-unstable 140.7.0esr
- nixpkgs-unstable 140.7.0esr
- nixos-unstable-small 140.7.0esr
-
nixos-25.11 140.7.0esr
- nixos-25.11-small 140.7.0esr
- nixpkgs-25.11-darwin 140.7.0esr
Ignored packages (28)
pkgs.firefoxpwa
Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)
pkgs.faust2firefox
The faust2firefox script, part of faust functional programming language for realtime audio signal processing
pkgs.firefox_decrypt
Tool to extract passwords from profiles of Mozilla Firefox and derivates
pkgs.pkgsRocm.firefox
Web browser built from Firefox source tree
pkgs.firefox-gnome-theme
GNOME theme for Firefox
pkgs.firefox-sync-client
Commandline-utility to list/view/edit/delete entries in a firefox-sync account.
pkgs.pkgsRocm.firefoxpwa
Tool to install, manage and use Progressive Web Apps (PWAs) in Mozilla Firefox (native component)
pkgs.pkgsRocm.thunderbird
Full-featured e-mail client
pkgs.pkgsRocm.firefox-beta
Web browser built from Firefox Beta Release source tree
pkgs.firefox-beta-unwrapped
Web browser built from Firefox Beta Release source tree
pkgs.pkgsRocm.firefox-mobile
Web browser built from Firefox source tree
pkgs.thunderbird-128-unwrapped
Full-featured e-mail client
pkgs.pkgsRocm.firefox-unwrapped
Web browser built from Firefox source tree
pkgs.pkgsRocm.firefox-devedition
Web browser built from Firefox Developer Edition source tree
pkgs.pkgsRocm.thunderbird-latest
Full-featured e-mail client
pkgs.firefox-devedition-unwrapped
Web browser built from Firefox Developer Edition source tree
pkgs.pkgsRocm.thunderbird-unwrapped
Full-featured e-mail client
pkgs.pkgsRocm.firefox-beta-unwrapped
Web browser built from Firefox Beta Release source tree
pkgs.gnomeExtensions.firefox-profiles
Easily launch Firefox with your favorite profile right from the indicator menu!
pkgs.roundcubePlugins.thunderbird_labels
None
pkgs.thunderbirdPackages.thunderbird-128
Full-featured e-mail client
pkgs.pkgsRocm.firefox-devedition-unwrapped
Web browser built from Firefox Developer Edition source tree
pkgs.pkgsRocm.thunderbird-latest-unwrapped
Full-featured e-mail client
pkgs.pkgsRocm.thunderbirdPackages.thunderbird
Full-featured e-mail client
pkgs.gnomeExtensions.firefox-pip-always-on-top
Automatically sets Picture-in-Picture windows to always be on top and visible on all workspaces
pkgs.gnomeExtensions.pip-alwaysontop-for-firefox
Enable Picture-in-Picture(PIP) mode to always be on for Firefox in Gnome.
pkgs.pkgsRocm.thunderbirdPackages.thunderbird-latest
Full-featured e-mail client
pkgs.vscode-extensions.firefox-devtools.vscode-firefox-debug
Visual Studio Code extension for debugging web applications and browser extensions in Firefox
Package maintainers
Ignored maintainers (4)
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@lovesegfault Bernardo Meurer <meurerbernardo@gmail.com>
-
@nbp Nicolas B. Pierron <nixos@nbp.name>
-
@vcunat Vladimír Čunát <v@cunat.cz>