<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for Mozilla Thunderbird</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2016:1769-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-07-10T18:30:29Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-07-10T18:30:29Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-07-10T18:30:29Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for Mozilla Thunderbird</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update contains Mozilla Thunderbird 45.2. (boo#983549)

It fixes security issues mostly affecting the e-mail program when used in a browser context, such as viewing a web page or HTMl formatted e-mail.

The following vulnerabilities were fixed:

- CVE-2016-2818, CVE-2016-2815: Memory safety bugs (boo#983549, MFSA2016-49)

Contains the following security fixes from the 45.1 release: (boo#977333)

- CVE-2016-2806, CVE-2016-2807: Miscellaneous memory safety hazards (boo#977375, boo#977376, MFSA 2016-39)

Contains the following security fixes from the 45.0 release: (boo#969894)

- CVE-2016-1952, CVE-2016-1953: Miscellaneous memory safety hazards (MFSA 2016-16)
- CVE-2016-1954: Local file overwriting and potential privilege escalation through CSP reports (MFSA 2016-17)
- CVE-2016-1955: CSP reports fail to strip location information for embedded iframe pages (MFSA 2016-18)
- CVE-2016-1956: Linux video memory DOS with Intel drivers (MFSA 2016-19)
- CVE-2016-1957: Memory leak in libstagefright when deleting an array during MP4 processing (MFSA 2016-20)
- CVE-2016-1960: Use-after-free in HTML5 string parser (MFSA 2016-23)
- CVE-2016-1961: Use-after-free in SetBody (MFSA 2016-24)
- CVE-2016-1964: Use-after-free during XML transformations (MFSA 2016-27)
- CVE-2016-1974: Out-of-bounds read in HTML parser following a failed allocation (MFSA 2016-34)

The graphite font shaping library was disabled, addressing the following font vulnerabilities:

- MFSA 2016-37/CVE-2016-1977/CVE-2016-2790/CVE-2016-2791/
  CVE-2016-2792/CVE-2016-2793/CVE-2016-2794/CVE-2016-2795/
  CVE-2016-2796/CVE-2016-2797/CVE-2016-2798/CVE-2016-2799/
  CVE-2016-2800/CVE-2016-2801/CVE-2016-2802

The following tracked packaging changes are included:

- fix build issues with gcc/binutils combination used in Leap 42.2 (boo#984637)
- gcc6 fixes (boo#986162)
- running on 48bit va aarch64 (boo#984126)</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2016-851</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      <Description>E-Mail link for openSUSE-SU-2016:1769-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/969894</URL>
      <Description>SUSE Bug 969894</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/977333</URL>
      <Description>SUSE Bug 977333</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/977375</URL>
      <Description>SUSE Bug 977375</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/977376</URL>
      <Description>SUSE Bug 977376</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/983549</URL>
      <Description>SUSE Bug 983549</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/984126</URL>
      <Description>SUSE Bug 984126</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/984637</URL>
      <Description>SUSE Bug 984637</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/986162</URL>
      <Description>SUSE Bug 986162</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1952/</URL>
      <Description>SUSE CVE CVE-2016-1952 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1953/</URL>
      <Description>SUSE CVE CVE-2016-1953 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1954/</URL>
      <Description>SUSE CVE CVE-2016-1954 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1955/</URL>
      <Description>SUSE CVE CVE-2016-1955 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1956/</URL>
      <Description>SUSE CVE CVE-2016-1956 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1957/</URL>
      <Description>SUSE CVE CVE-2016-1957 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1960/</URL>
      <Description>SUSE CVE CVE-2016-1960 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1961/</URL>
      <Description>SUSE CVE CVE-2016-1961 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1964/</URL>
      <Description>SUSE CVE CVE-2016-1964 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1974/</URL>
      <Description>SUSE CVE CVE-2016-1974 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-1977/</URL>
      <Description>SUSE CVE CVE-2016-1977 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2790/</URL>
      <Description>SUSE CVE CVE-2016-2790 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2791/</URL>
      <Description>SUSE CVE CVE-2016-2791 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2792/</URL>
      <Description>SUSE CVE CVE-2016-2792 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2793/</URL>
      <Description>SUSE CVE CVE-2016-2793 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2794/</URL>
      <Description>SUSE CVE CVE-2016-2794 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2795/</URL>
      <Description>SUSE CVE CVE-2016-2795 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2796/</URL>
      <Description>SUSE CVE CVE-2016-2796 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2797/</URL>
      <Description>SUSE CVE CVE-2016-2797 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2798/</URL>
      <Description>SUSE CVE CVE-2016-2798 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2799/</URL>
      <Description>SUSE CVE CVE-2016-2799 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2800/</URL>
      <Description>SUSE CVE CVE-2016-2800 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2801/</URL>
      <Description>SUSE CVE CVE-2016-2801 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2802/</URL>
      <Description>SUSE CVE CVE-2016-2802 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2806/</URL>
      <Description>SUSE CVE CVE-2016-2806 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2807/</URL>
      <Description>SUSE CVE CVE-2016-2807 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2815/</URL>
      <Description>SUSE CVE CVE-2016-2815 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2016-2818/</URL>
      <Description>SUSE CVE CVE-2016-2818 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Package Hub 12">
      <Branch Type="Product Name" Name="SUSE Package Hub 12">
        <FullProductName ProductID="SUSE Package Hub 12" CPE="cpe:/o:suse:packagehub:12">SUSE Package Hub 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="MozillaThunderbird-45.2-6.1">
      <FullProductName ProductID="MozillaThunderbird-45.2-6.1">MozillaThunderbird-45.2-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="MozillaThunderbird-buildsymbols-45.2-6.1">
      <FullProductName ProductID="MozillaThunderbird-buildsymbols-45.2-6.1">MozillaThunderbird-buildsymbols-45.2-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="MozillaThunderbird-devel-45.2-6.1">
      <FullProductName ProductID="MozillaThunderbird-devel-45.2-6.1">MozillaThunderbird-devel-45.2-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="MozillaThunderbird-translations-common-45.2-6.1">
      <FullProductName ProductID="MozillaThunderbird-translations-common-45.2-6.1">MozillaThunderbird-translations-common-45.2-6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="MozillaThunderbird-translations-other-45.2-6.1">
      <FullProductName ProductID="MozillaThunderbird-translations-other-45.2-6.1">MozillaThunderbird-translations-other-45.2-6.1</FullProductName>
    </Branch>
    <Relationship ProductReference="MozillaThunderbird-45.2-6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:MozillaThunderbird-45.2-6.1">MozillaThunderbird-45.2-6.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-buildsymbols-45.2-6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1">MozillaThunderbird-buildsymbols-45.2-6.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-devel-45.2-6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1">MozillaThunderbird-devel-45.2-6.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-common-45.2-6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1">MozillaThunderbird-translations-common-45.2-6.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaThunderbird-translations-other-45.2-6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 12">
      <FullProductName ProductID="SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1">MozillaThunderbird-translations-other-45.2-6.1 as a component of SUSE Package Hub 12</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</Note>
    </Notes>
    <CVE>CVE-2016-1952</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1952.html</URL>
        <Description>CVE-2016-1952</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.</Note>
    </Notes>
    <CVE>CVE-2016-1953</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1953.html</URL>
        <Description>CVE-2016-1953</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a URL of a local file.</Note>
    </Notes>
    <CVE>CVE-2016-1954</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1954.html</URL>
        <Description>CVE-2016-1954</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.</Note>
    </Notes>
    <CVE>CVE-2016-1955</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1955.html</URL>
        <Description>CVE-2016-1955</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970257</URL>
        <Description>SUSE Bug 970257</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970377</URL>
        <Description>SUSE Bug 970377</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970378</URL>
        <Description>SUSE Bug 970378</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970379</URL>
        <Description>SUSE Bug 970379</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970380</URL>
        <Description>SUSE Bug 970380</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970381</URL>
        <Description>SUSE Bug 970381</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970431</URL>
        <Description>SUSE Bug 970431</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970433</URL>
        <Description>SUSE Bug 970433</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.</Note>
    </Notes>
    <CVE>CVE-2016-1956</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>5.1</BaseScore>
        <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>7.1</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1956.html</URL>
        <Description>CVE-2016-1956</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970257</URL>
        <Description>SUSE Bug 970257</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970377</URL>
        <Description>SUSE Bug 970377</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970378</URL>
        <Description>SUSE Bug 970378</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970379</URL>
        <Description>SUSE Bug 970379</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970380</URL>
        <Description>SUSE Bug 970380</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970381</URL>
        <Description>SUSE Bug 970381</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970431</URL>
        <Description>SUSE Bug 970431</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/970433</URL>
        <Description>SUSE Bug 970433</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.</Note>
    </Notes>
    <CVE>CVE-2016-1957</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>4.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1957.html</URL>
        <Description>CVE-2016-1957</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.</Note>
    </Notes>
    <CVE>CVE-2016-1960</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1960.html</URL>
        <Description>CVE-2016-1960</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574.</Note>
    </Notes>
    <CVE>CVE-2016-1961</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1961.html</URL>
        <Description>CVE-2016-1961</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.</Note>
    </Notes>
    <CVE>CVE-2016-1964</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1964.html</URL>
        <Description>CVE-2016-1964</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.</Note>
    </Notes>
    <CVE>CVE-2016-1974</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1974.html</URL>
        <Description>CVE-2016-1974</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-1977</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-1977.html</URL>
        <Description>CVE-2016-1977</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-2790</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2790.html</URL>
        <Description>CVE-2016-2790</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="13">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-2791</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2791.html</URL>
        <Description>CVE-2016-2791</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="14">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2800.</Note>
    </Notes>
    <CVE>CVE-2016-2792</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2792.html</URL>
        <Description>CVE-2016-2792</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="15">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-2793</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2793.html</URL>
        <Description>CVE-2016-2793</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="16">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-2794</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2794.html</URL>
        <Description>CVE-2016-2794</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="17">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-2795</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2795.html</URL>
        <Description>CVE-2016-2795</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="18">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-2796</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2796.html</URL>
        <Description>CVE-2016-2796</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="19">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801.</Note>
    </Notes>
    <CVE>CVE-2016-2797</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2797.html</URL>
        <Description>CVE-2016-2797</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="20">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-2798</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2798.html</URL>
        <Description>CVE-2016-2798</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="21">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-2799</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>9.3</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2799.html</URL>
        <Description>CVE-2016-2799</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="22">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2792.</Note>
    </Notes>
    <CVE>CVE-2016-2800</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2800.html</URL>
        <Description>CVE-2016-2800</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="23">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2797.</Note>
    </Notes>
    <CVE>CVE-2016-2801</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2801.html</URL>
        <Description>CVE-2016-2801</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="24">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.</Note>
    </Notes>
    <CVE>CVE-2016-2802</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2802.html</URL>
        <Description>CVE-2016-2802</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/969894</URL>
        <Description>SUSE Bug 969894</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="25">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</Note>
    </Notes>
    <CVE>CVE-2016-2806</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>10</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2806.html</URL>
        <Description>CVE-2016-2806</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/977375</URL>
        <Description>SUSE Bug 977375</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="26">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</Note>
    </Notes>
    <CVE>CVE-2016-2807</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>10</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2807.html</URL>
        <Description>CVE-2016-2807</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/977333</URL>
        <Description>SUSE Bug 977333</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/977376</URL>
        <Description>SUSE Bug 977376</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="27">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</Note>
    </Notes>
    <CVE>CVE-2016-2815</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2815.html</URL>
        <Description>CVE-2016-2815</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/983549</URL>
        <Description>SUSE Bug 983549</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/983638</URL>
        <Description>SUSE Bug 983638</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="28">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.</Note>
    </Notes>
    <CVE>CVE-2016-2818</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-buildsymbols-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-devel-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-common-45.2-6.1</ProductID>
        <ProductID>SUSE Package Hub 12:MozillaThunderbird-translations-other-45.2-6.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
      <ScoreSet>
        <BaseScore>6.8</BaseScore>
        <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5/#IT5Z2MQVCUU2PY7AOHLQUFDN44PCYHX5</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-2818.html</URL>
        <Description>CVE-2016-2818</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/983549</URL>
        <Description>SUSE Bug 983549</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/983638</URL>
        <Description>SUSE Bug 983638</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
