Debian Firefox-Esr vulnerabilities

1,071 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
1,071
CISA KEV
11
actively exploited
Public exploits
23
Exploited in wild
15
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW125

Vulnerabilities

Page 10 of 54
CVE-2025-4084LOWCVSS 5.72025
CVE-2025-4084 [MEDIUM] CVE-2025-4084: firefox-esr - Due to insufficient escaping of the special characters in the "copy as cURL" fea... Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox ESR < 128.10, Firefox ESR < 115.23
debian
CVE-2025-11713LOWCVSS 8.12025
CVE-2025-11713 [HIGH] CVE-2025-11713: firefox - Insufficient escaping in the “Copy as cURL” feature could have been used to tric... Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code on Windows. This did not affect the application when running on other operating systems. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4. Scope: local sid: resolved
debian
CVE-2025-2857LOWCVSS 8.32025
CVE-2025-2857 [HIGH] CVE-2025-2857: firefox - Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox deve... Following the recent Chrome sandbox escape (CVE-2025-2783), various Firefox developers identified a similar pattern in our IPC code. A compromised child process could cause the parent process to return an unintentionally powerful handle, leading to a sandbox escape. The original vulnerability was being exploited in the wild. *This only affects Firefox on Windows. Othe
debian
CVE-2025-5265LOWCVSS 4.82025
CVE-2025-5265 [MEDIUM] CVE-2025-5265: firefox - Due to insufficient escaping of the ampersand character in the “Copy as cURL” fe... Due to insufficient escaping of the ampersand character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. *This bug only affects Firefox for Windows. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox
debian
CVE-2025-6426LOWCVSS 8.82025
CVE-2025-6426 [HIGH] CVE-2025-6426: firefox - The executable file warning did not warn users before opening files with the `te... The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. Scope: local sid: resolved
debian
CVE-2025-4082LOWCVSS 5.92025
CVE-2025-4082 [MEDIUM] CVE-2025-4082: firefox - Modification of specific WebGL shader attributes could trigger an out-of-bounds ... Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138
debian
CVE-2025-1930LOWCVSS 8.82025
CVE-2025-1930 [HIGH] CVE-2025-1930: firefox - On Windows, a compromised content process could use bad StreamData sent over Aud... On Windows, a compromised content process could use bad StreamData sent over AudioIPC to trigger a use-after-free in the Browser process. This could have led to a sandbox escape. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. Scope: local sid: resolved
debian
CVE-2025-13015LOWCVSS 3.4fixed in firefox 145.0-1 (sid)2025
CVE-2025-13015 [LOW] CVE-2025-13015: firefox - Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR... Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5. Scope: local sid: resolved (fixed in 145.0-1)
debian
CVE-2025-2817LOWCVSS 8.82025
CVE-2025-2817 [HIGH] CVE-2025-2817: firefox - Thunderbird's update mechanism allowed a medium-integrity user process to interf... Thunderbird's update mechanism allowed a medium-integrity user process to interfere with the SYSTEM-level updater by manipulating the file-locking behavior. By injecting code into the user-privileged process, an attacker could bypass intended access controls, allowing SYSTEM-level file operations on paths controlled by a non-privileged user and enabling privilege esca
debian
CVE-2024-9680CRITICALCVSS 9.8KEVfixed in firefox 131.0.2-1 (sid)2024
CVE-2024-9680 [CRITICAL] CVE-2024-9680: firefox - An attacker was able to achieve code execution in the content process by exploit... An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines. We have had reports of this vulnerability being exploited in the wild. This vulnerability affects Firefox < 131.0.2, Firefox ESR < 128.3.1, Firefox ESR < 115.16.1, Thunderbird < 131.0.1, Thunderbird < 128.3.1, and Thunderbird < 115.16.0. Sco
debian
CVE-2024-6602CRITICALCVSS 9.8fixed in firefox 128.0-1 (sid)2024
CVE-2024-6602 [CRITICAL] CVE-2024-6602: firefox - A mismatch between allocator and deallocator could have led to memory corruption... A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128. Scope: local sid: resolved (fixed in 128.0-1)
debian
CVE-2024-8384CRITICALCVSS 9.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8384 [CRITICAL] CVE-2024-8384: firefox - The JavaScript garbage collector could mis-color cross-compartment objects if OO... The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15. Scope: local sid: resolved (fixed in 130.0-1)
debian
CVE-2024-8381CRITICALCVSS 9.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8381 [CRITICAL] CVE-2024-8381: firefox - A potentially exploitable type confusion could be triggered when looking up a pr... A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15. Scope: local sid: resolved (fixed in 130.0-1)
debian
CVE-2024-11704CRITICALCVSS 9.8fixed in firefox 134.0-1 (sid)2024
CVE-2024-11704 [CRITICAL] CVE-2024-11704: firefox - A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` w... A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7. Scope: local sid: resolved (
debian
CVE-2024-9401CRITICALCVSS 9.8fixed in firefox 131.0-1 (sid)2024
CVE-2024-9401 [CRITICAL] CVE-2024-9401: firefox - Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2... Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.
debian
CVE-2024-7519CRITICALCVSS 9.6fixed in firefox 129.0-1 (sid)2024
CVE-2024-7519 [CRITICAL] CVE-2024-7519: firefox - Insufficient checks when processing graphics shared memory could have led to mem... Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14. Scope: local sid: resolved (fixed in 129.0-1)
debian
CVE-2024-9392CRITICALCVSS 9.8fixed in firefox 131.0-1 (sid)2024
CVE-2024-9392 [CRITICAL] CVE-2024-9392: firefox - A compromised content process could have allowed for the arbitrary loading of cr... A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131. Scope: local sid: resolved (fixed in 131.0-1)
debian
CVE-2024-1553HIGHCVSS 8.1fixed in firefox 123.0-1 (sid)2024
CVE-2024-1553 [HIGH] CVE-2024-1553: firefox - Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 11... Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. Scope: local sid: resolved (fixed in 12
debian
CVE-2024-4777HIGHCVSS 8.8fixed in firefox 126.0-1 (sid)2024
CVE-2024-4777 [HIGH] CVE-2024-4777: firefox - Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 1... Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Scope: local sid: resolved (fixed i
debian
CVE-2024-3854HIGHCVSS 8.8fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3854 [HIGH] CVE-2024-3854: firefox - In some code patterns the JIT incorrectly optimized switch statements and genera... In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
Debian Firefox-Esr vulnerabilities | cvebase