SUSE SLES12: MozillaFirefox / MozillaFirefox-devel / etc (SUSE-SU-2026:4247-1)

high Nessus Plugin ID 347906

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 / SLES_SAP12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4247-1 advisory.

Update to Firefox Extended Support Release 153.3.0 ESRi (MFSA 2026-93, bsc#1280371)

- CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component.
- CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component.
- CVE-2026-92015: Privilege escalation in the WebExtensions component.
- CVE-2026-92016: Use-after-free in the Disability Access APIs component.
- CVE-2026-92017: Privilege escalation in the DOM: Service Workers component.
- CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component.
- CVE-2026-92019: Mitigation bypass in the Remote Settings Client component.
- CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component.
- CVE-2026-92022: Use-after-free in the DOM: HTML Parser component.
- CVE-2026-92023: Use-after-free in the XML component.
- CVE-2026-92024: Use-after-free in the SVG component.
- CVE-2026-92025: Use-after-free in the DOM: Navigation component.
- CVE-2026-92026: Use-after-free in the Networking component.
- CVE-2026-92027: Use-after-free in the DOM: Streams component.
- CVE-2026-92028: Use-after-free in the DOM: Core & HTML component.
- CVE-2026-92029: Use-after-free in the SVG component.
- CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component.
- CVE-2026-92031: Information disclosure in the Graphics: ImageLib component.
- CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component.
- CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component.
- CVE-2026-92038: Mitigation bypass in the Remote Settings Client component.
- CVE-2026-92039: Mitigation bypass in the DOM: Notifications component.
- CVE-2026-92041: Mitigation bypass in the DOM: Networking component.
- CVE-2026-92042: Race condition in the DOM: Content Processes component.
- CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component.
- CVE-2026-92044: Information disclosure in the Networking: HTTP component.
- CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component.
- CVE-2026-92046: Use-after-free in the Graphics component.
- CVE-2026-92047: Privilege escalation in the Crash Reporting component.
- CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
- CVE-2026-92049: Use-after-free in the Widget: Win32 component.
- CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component.
- CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component.
- CVE-2026-92054: Privilege escalation in the Memory component.
- CVE-2026-92055: Privilege escalation in the DevTools component.
- CVE-2026-92056: Use-after-free in the Graphics: Text component.
- CVE-2026-92057: Mitigation bypass in the Enterprise Policies component.
- CVE-2026-92058: Use-after-free in the Graphics component.
- CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component.
- CVE-2026-92060: Use-after-free in the Internationalization component.
- CVE-2026-92062: Privilege escalation in the Session Restore component.
- CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
- CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
- CVE-2026-92067: Use-after-free in the Widget: Gtk component.
- CVE-2026-92068: Site isolation issue in the Reader Mode component.
- CVE-2026-92069: Spoofing issue in the DOM: Navigation component.
- CVE-2026-92070: Information disclosure in the Networking component.
- CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component.
- CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component.
- CVE-2026-92073: Privilege escalation in the Enterprise Policies component.
- CVE-2026-92074: Mitigation bypass in the Popup Blocker component.
- CVE-2026-92075: Mitigation bypass in the Networking component.
- CVE-2026-92076: Incorrect boundary conditions in the Networking component.
- CVE-2026-92077: Denial-of-service in the SVG component.
- CVE-2026-92078: Denial-of-service in the Security component.
- CVE-2026-92079: Mitigation bypass in the Widget: Win32 component.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected MozillaFirefox, MozillaFirefox-devel and / or MozillaFirefox-translations-common packages.

See Also

https://bugzilla.suse.com/1280371

https://www.suse.com/security/cve/CVE-2026-92005

https://www.suse.com/security/cve/CVE-2026-92006

https://www.suse.com/security/cve/CVE-2026-92007

https://www.suse.com/security/cve/CVE-2026-92008

https://www.suse.com/security/cve/CVE-2026-92009

https://www.suse.com/security/cve/CVE-2026-92010

https://www.suse.com/security/cve/CVE-2026-92011

https://www.suse.com/security/cve/CVE-2026-92012

https://www.suse.com/security/cve/CVE-2026-92013

https://www.suse.com/security/cve/CVE-2026-92015

https://www.suse.com/security/cve/CVE-2026-92016

https://www.suse.com/security/cve/CVE-2026-92017

https://www.suse.com/security/cve/CVE-2026-92018

https://www.suse.com/security/cve/CVE-2026-92019

https://www.suse.com/security/cve/CVE-2026-92020

https://www.suse.com/security/cve/CVE-2026-92022

https://www.suse.com/security/cve/CVE-2026-92023

https://www.suse.com/security/cve/CVE-2026-92024

https://www.suse.com/security/cve/CVE-2026-92025

https://www.suse.com/security/cve/CVE-2026-92026

https://www.suse.com/security/cve/CVE-2026-92027

https://www.suse.com/security/cve/CVE-2026-92028

https://www.suse.com/security/cve/CVE-2026-92029

https://www.suse.com/security/cve/CVE-2026-92030

https://www.suse.com/security/cve/CVE-2026-92031

https://www.suse.com/security/cve/CVE-2026-92032

https://www.suse.com/security/cve/CVE-2026-92035

https://www.suse.com/security/cve/CVE-2026-92038

https://www.suse.com/security/cve/CVE-2026-92039

https://www.suse.com/security/cve/CVE-2026-92041

https://www.suse.com/security/cve/CVE-2026-92042

https://www.suse.com/security/cve/CVE-2026-92043

https://www.suse.com/security/cve/CVE-2026-92044

https://www.suse.com/security/cve/CVE-2026-92045

https://www.suse.com/security/cve/CVE-2026-92046

https://www.suse.com/security/cve/CVE-2026-92047

https://www.suse.com/security/cve/CVE-2026-92048

https://www.suse.com/security/cve/CVE-2026-92049

https://www.suse.com/security/cve/CVE-2026-92052

https://www.suse.com/security/cve/CVE-2026-92053

https://www.suse.com/security/cve/CVE-2026-92054

https://www.suse.com/security/cve/CVE-2026-92055

https://www.suse.com/security/cve/CVE-2026-92056

https://www.suse.com/security/cve/CVE-2026-92057

https://www.suse.com/security/cve/CVE-2026-92058

https://www.suse.com/security/cve/CVE-2026-92059

https://www.suse.com/security/cve/CVE-2026-92060

https://www.suse.com/security/cve/CVE-2026-92062

https://www.suse.com/security/cve/CVE-2026-92064

https://www.suse.com/security/cve/CVE-2026-92065

https://www.suse.com/security/cve/CVE-2026-92067

https://www.suse.com/security/cve/CVE-2026-92068

https://www.suse.com/security/cve/CVE-2026-92069

https://www.suse.com/security/cve/CVE-2026-92070

https://www.suse.com/security/cve/CVE-2026-92071

https://www.suse.com/security/cve/CVE-2026-92072

https://www.suse.com/security/cve/CVE-2026-92073

https://www.suse.com/security/cve/CVE-2026-92074

https://www.suse.com/security/cve/CVE-2026-92075

https://www.suse.com/security/cve/CVE-2026-92076

https://www.suse.com/security/cve/CVE-2026-92077

https://www.suse.com/security/cve/CVE-2026-92078

https://www.suse.com/security/cve/CVE-2026-92079

http://www.nessus.org/u?842c40b1

Plugin Details

Severity: High

ID: 347906

File Name: suse_SU-2026-4247-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 93.34

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-92073

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:mozillafirefox-devel, p-cpe:/a:novell:suse_linux:mozillafirefox-translations-common, p-cpe:/a:novell:suse_linux:mozillafirefox

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 9/17/2026

Vulnerability Publication Date: 9/15/2026

Reference Information

CVE: CVE-2026-92005, CVE-2026-92006, CVE-2026-92007, CVE-2026-92008, CVE-2026-92009, CVE-2026-92010, CVE-2026-92011, CVE-2026-92012, CVE-2026-92013, CVE-2026-92015, CVE-2026-92016, CVE-2026-92017, CVE-2026-92018, CVE-2026-92019, CVE-2026-92020, CVE-2026-92022, CVE-2026-92023, CVE-2026-92024, CVE-2026-92025, CVE-2026-92026, CVE-2026-92027, CVE-2026-92028, CVE-2026-92029, CVE-2026-92030, CVE-2026-92031, CVE-2026-92032, CVE-2026-92035, CVE-2026-92038, CVE-2026-92039, CVE-2026-92041, CVE-2026-92042, CVE-2026-92043, CVE-2026-92044, CVE-2026-92045, CVE-2026-92046, CVE-2026-92047, CVE-2026-92048, CVE-2026-92049, CVE-2026-92052, CVE-2026-92053, CVE-2026-92054, CVE-2026-92055, CVE-2026-92056, CVE-2026-92057, CVE-2026-92058, CVE-2026-92059, CVE-2026-92060, CVE-2026-92062, CVE-2026-92064, CVE-2026-92065, CVE-2026-92067, CVE-2026-92068, CVE-2026-92069, CVE-2026-92070, CVE-2026-92071, CVE-2026-92072, CVE-2026-92073, CVE-2026-92074, CVE-2026-92075, CVE-2026-92076, CVE-2026-92077, CVE-2026-92078, CVE-2026-92079

SuSE: SUSE-SU-2026:4247-1