gpp_maybe Security update for mozillafirefox
SUSE-SLE-Module-Desktop-Applications-15-SP7-2025-3775


This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 140.4.0 ESR (bsc#1251263). - CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance() - CVE-2025-11709: Out of bounds read/write in a privileged process triggered by WebGL textures - CVE-2025-11710: Cross-process information leaked due to malicious IPC messages - CVE-2025-11711: Some non-writable Object properties could be modified - CVE-2025-11712: An OBJECT tag type attribute overrode browser behavior on web resources without a content-type - CVE-2025-11713: Potential user-assisted code execution in “Copy as cURL” command - CVE-2025-11714: Memory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144 - CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144

  • Release Date
    Oct 24 2025
  • References
    Bugzilla: 1251263
  • Type
    security
  • Severity
    important

cloud_download Downloads

Desktop Applications Module 15.7 aarch64
Desktop Applications Module 15.7 ppc64le
Desktop Applications Module 15.7 x86_64
Desktop Applications Module 15.7 s390x