mozilla -- multiple vulnerabilities

Affected packages
firefox < 65.0_1,1
waterfox < 56.2.7
linux-seamonkey < 2.53.0
seamonkey < 2.53.0
firefox-esr < 60.5.0_1,1
linux-firefox < 60.5.0,2
libxul < 60.5.0
linux-thunderbird < 60.5.0
thunderbird < 60.5.0


VuXML ID b1f7d52f-fc42-48e8-8403-87d4c9d26229
Discovery 2019-01-29
Entry 2019-01-29
Modified 2019-07-23

Mozilla Foundation reports:

CVE-2018-18500: Use-after-free parsing HTML5 stream

CVE-2018-18503: Memory corruption with Audio Buffer

CVE-2018-18504: Memory corruption and out-of-bounds read of texture client buffer

CVE-2018-18505: Privilege escalation through IPC channel messages

CVE-2018-18506: Proxy Auto-Configuration file can define localhost access to be proxied

CVE-2018-18502: Memory safety bugs fixed in Firefox 65

CVE-2018-18501: Memory safety bugs fixed in Firefox 65 and Firefox ESR 60.5


