<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for MozillaFirefox</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2018:0374-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2018-02-06T10:47:56Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2018-02-06T10:47:56Z</InitialReleaseDate>
    <CurrentReleaseDate>2018-02-06T10:47:56Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for MozillaFirefox</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for MozillaFirefox to version 52.6 several issues.

These security issues were fixed:

- CVE-2018-5091: Use-after-free with DTMF timers (bsc#1077291).
- CVE-2018-5095: Integer overflow in Skia library during edge builder allocation (bsc#1077291).
- CVE-2018-5096: Use-after-free while editing form elements (bsc#1077291).
- CVE-2018-5097: Use-after-free when source document is manipulated during XSLT (bsc#1077291).
- CVE-2018-5098: Use-after-free while manipulating form input elements (bsc#1077291).
- CVE-2018-5099: Use-after-free with widget listener (bsc#1077291).
- CVE-2018-5104: Use-after-free during font face manipulation (bsc#1077291).
- CVE-2018-5089: Fixed several memory safety bugs (bsc#1077291).
- CVE-2018-5117: URL spoofing with right-to-left text aligned left-to-right (bsc#1077291).
- CVE-2018-5102: Use-after-free in HTML media elements (bsc#1077291).
- CVE-2018-5103: Use-after-free during mouse event handling (bsc#1077291).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-OpenStack-Cloud-6-2018-263,SUSE-SLE-DESKTOP-12-SP2-2018-263,SUSE-SLE-DESKTOP-12-SP3-2018-263,SUSE-SLE-RPI-12-SP2-2018-263,SUSE-SLE-SAP-12-SP1-2018-263,SUSE-SLE-SDK-12-SP2-2018-263,SUSE-SLE-SDK-12-SP3-2018-263,SUSE-SLE-SERVER-12-2018-263,SUSE-SLE-SERVER-12-SP1-2018-263,SUSE-SLE-SERVER-12-SP2-2018-263,SUSE-SLE-SERVER-12-SP3-2018-263</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      <Description>Link for SUSE-SU-2018:0374-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/opensuse-security-announce/2018-02/msg00007.html</URL>
      <Description>E-Mail link for SUSE-SU-2018:0374-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1077291</URL>
      <Description>SUSE Bug 1077291</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5089/</URL>
      <Description>SUSE CVE CVE-2018-5089 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5091/</URL>
      <Description>SUSE CVE CVE-2018-5091 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5095/</URL>
      <Description>SUSE CVE CVE-2018-5095 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5096/</URL>
      <Description>SUSE CVE CVE-2018-5096 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5097/</URL>
      <Description>SUSE CVE CVE-2018-5097 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5098/</URL>
      <Description>SUSE CVE CVE-2018-5098 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5099/</URL>
      <Description>SUSE CVE CVE-2018-5099 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5102/</URL>
      <Description>SUSE CVE CVE-2018-5102 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5103/</URL>
      <Description>SUSE CVE CVE-2018-5103 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5104/</URL>
      <Description>SUSE CVE CVE-2018-5104 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-5117/</URL>
      <Description>SUSE CVE CVE-2018-5117 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2" CPE="cpe:/o:suse:sled:12:sp2">SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP3" CPE="cpe:/o:suse:sled:12:sp3">SUSE Linux Enterprise Desktop 12 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP1-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS" CPE="cpe:/o:suse:sles-ltss:12:sp1">SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2" CPE="cpe:/o:suse:sles:12:sp2">SUSE Linux Enterprise Server 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3" CPE="cpe:/o:suse:sles:12:sp3">SUSE Linux Enterprise Server 12 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 12-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS" CPE="cpe:/o:suse:sles-ltss:12">SUSE Linux Enterprise Server 12-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2" CPE="cpe:/o:suse:sles:12:sp2">SUSE Linux Enterprise Server for Raspberry Pi 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1" CPE="cpe:/o:suse:sles_sap:12:sp1">SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2" CPE="cpe:/o:suse:sles_sap:12:sp2">SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3" CPE="cpe:/o:suse:sles_sap:12:sp3">SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP2" CPE="cpe:/o:suse:sle-sdk:12:sp2">SUSE Linux Enterprise Software Development Kit 12 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Software Development Kit 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Software Development Kit 12 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP3" CPE="cpe:/o:suse:sle-sdk:12:sp3">SUSE Linux Enterprise Software Development Kit 12 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 6">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 6">
        <FullProductName ProductID="SUSE OpenStack Cloud 6" CPE="cpe:/o:suse:suse-openstack-cloud:6">SUSE OpenStack Cloud 6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="MozillaFirefox-52.6.0esr-109.13.1">
      <FullProductName ProductID="MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="MozillaFirefox-devel-52.6.0esr-109.13.1">
      <FullProductName ProductID="MozillaFirefox-devel-52.6.0esr-109.13.1">MozillaFirefox-devel-52.6.0esr-109.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="MozillaFirefox-translations-52.6.0esr-109.13.1">
      <FullProductName ProductID="MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1</FullProductName>
    </Branch>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Desktop 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Desktop 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Desktop 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-devel-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1">MozillaFirefox-devel-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP1-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12 SP1-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-devel-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1">MozillaFirefox-devel-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 12-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server 12-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server for Raspberry Pi 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server for Raspberry Pi 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-devel-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1">MozillaFirefox-devel-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP1">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Server for SAP Applications 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-devel-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1">MozillaFirefox-devel-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-devel-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Software Development Kit 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1">MozillaFirefox-devel-52.6.0esr-109.13.1 as a component of SUSE Linux Enterprise Software Development Kit 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1">MozillaFirefox-52.6.0esr-109.13.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-devel-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1">MozillaFirefox-devel-52.6.0esr-109.13.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="MozillaFirefox-translations-52.6.0esr-109.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1">MozillaFirefox-translations-52.6.0esr-109.13.1 as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird &lt; 52.6, Firefox ESR &lt; 52.6, and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5089</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5089.html</URL>
        <Description>CVE-2018-5089</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR &lt; 52.6 and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5091</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5091.html</URL>
        <Description>CVE-2018-5091</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird &lt; 52.6, Firefox ESR &lt; 52.6, and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5095</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5095.html</URL>
        <Description>CVE-2018-5095</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR &lt; 52.6 and Thunderbird &lt; 52.6.</Note>
    </Notes>
    <CVE>CVE-2018-5096</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5096.html</URL>
        <Description>CVE-2018-5096</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash. This vulnerability affects Thunderbird &lt; 52.6, Firefox ESR &lt; 52.6, and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5097</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5097.html</URL>
        <Description>CVE-2018-5097</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird &lt; 52.6, Firefox ESR &lt; 52.6, and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5098</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5098.html</URL>
        <Description>CVE-2018-5098</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects Thunderbird &lt; 52.6, Firefox ESR &lt; 52.6, and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5099</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5099.html</URL>
        <Description>CVE-2018-5099</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird &lt; 52.6, Firefox ESR &lt; 52.6, and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5102</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5102.html</URL>
        <Description>CVE-2018-5102</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird &lt; 52.6, Firefox ESR &lt; 52.6, and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5103</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5103.html</URL>
        <Description>CVE-2018-5103</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird &lt; 52.6, Firefox ESR &lt; 52.6, and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5104</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5104.html</URL>
        <Description>CVE-2018-5104</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird &lt; 52.6, Firefox ESR &lt; 52.6, and Firefox &lt; 58.</Note>
    </Notes>
    <CVE>CVE-2018-5117</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP1-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server 12-LTSS:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP1:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP2:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 12 SP3:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP2:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE Linux Enterprise Software Development Kit 12 SP3:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-devel-52.6.0esr-109.13.1</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:MozillaFirefox-translations-52.6.0esr-109.13.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2018/suse-su-20180374-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-5117.html</URL>
        <Description>CVE-2018-5117</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1077291</URL>
        <Description>SUSE Bug 1077291</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
