Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 15 of 49
CVE-2020-26973P3HIGHCVSS 8.8fixed in firefox 84.0-1 (sid)2020
CVE-2020-26973 [HIGH] CVE-2020-26973: firefox - Certain input to the CSS Sanitizer confused it, resulting in incorrect component...
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
Scope: local
sid: resolved (fixed in 84.0-1)
debian
CVE-2021-23987P3HIGHCVSS 8.8fixed in firefox 87.0-1 (sid)2021
CVE-2021-23987 [HIGH] CVE-2021-23987: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
Scope: local
debian
CVE-2021-29989P3HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29989 [HIGH] CVE-2021-29989: firefox - Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.13, Firefox ESR < 78.13, and Firefox < 91.
Scope: local
sid: resolved (fix
debian
CVE-2021-29976P3HIGHCVSS 8.8fixed in firefox 90.0-1 (sid)2021
CVE-2021-29976 [HIGH] CVE-2021-29976: firefox - Mozilla developers reported memory safety bugs present in code shared between Fi...
Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
Scope: local
sid: re
debian
CVE-2021-38493P3HIGHCVSS 8.8fixed in firefox 92.0-1 (sid)2021
CVE-2021-38493 [HIGH] CVE-2021-38493: firefox - Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.
Scope: local
sid: resolved (fix
debian
CVE-2017-5469P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5469 [CRITICAL] CVE-2017-5469: firefox - Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 ...
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2023-6863P3HIGHCVSS 8.8fixed in firefox 121.0-1 (sid)2023
CVE-2023-6863 [HIGH] CVE-2023-6863: firefox - The `ShutdownObserver()` was susceptible to potentially undefined behavior due t...
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
debian
CVE-2022-46874P3HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46874 [HIGH] CVE-2022-46874: firefox - A file with a long filename could have had its filename truncated to remove the ...
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting i
debian
CVE-2022-22751P3HIGHCVSS 8.8fixed in firefox 96.0-1 (sid)2022
CVE-2022-22751 [HIGH] CVE-2022-22751: firefox - Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratz...
Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve Fink reported memory safety bugs present in Firefox 95 and Firefox ESR 91.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary
debian
CVE-2023-4585P3HIGHCVSS 8.8fixed in firefox 117.0-1 (sid)2023
CVE-2023-4585 [HIGH] CVE-2023-4585: firefox - Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 11...
Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
Scope: local
sid: resolved (fixed in 11
debian
CVE-2023-32215P3HIGHCVSS 8.8fixed in firefox 113.0-1 (sid)2023
CVE-2023-32215 [HIGH] CVE-2023-32215: firefox - Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily M...
Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112 and Firefox ESR 102.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to r
debian
CVE-2023-28176P3HIGHCVSS 8.8fixed in firefox 111.0-1 (sid)2023
CVE-2023-28176 [HIGH] CVE-2023-28176: firefox - Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these b...
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Scope: local
sid: resolved (fixed in 111.0-1)
debian
CVE-2023-23605P3HIGHCVSS 8.8fixed in firefox 109.0-1 (sid)2023
CVE-2023-23605 [HIGH] CVE-2023-23605: firefox - Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs pres...
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
debian
CVE-2023-29550P3HIGHCVSS 8.8fixed in firefox 112.0-1 (sid)2023
CVE-2023-29550 [HIGH] CVE-2023-29550: firefox - Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these b...
Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
Sco
debian
CVE-2023-29536P3HIGHCVSS 8.8fixed in firefox 112.0-1 (sid)2023
CVE-2023-29536 [HIGH] CVE-2023-29536: firefox - An attacker could cause the memory manager to incorrectly free a pointer that ad...
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
Scope: local
sid: resolved (
debian
CVE-2023-28162P3HIGHCVSS 8.8fixed in firefox 111.0-1 (sid)2023
CVE-2023-28162 [HIGH] CVE-2023-28162: firefox - While implementing AudioWorklets, some code may have casted one type to another,...
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Scope: local
sid: resolved (fixed in 111.0-1)
debian
CVE-2023-25737P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25737 [HIGH] CVE-2023-25737: firefox - An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> coul...
An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2023-25739P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25739 [HIGH] CVE-2023-25739: firefox - Module load requests that failed were not being checked as to whether or not the...
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in ScriptLoadContext. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2018-5188P3CRITICALCVSS 9.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-5188 [CRITICAL] CVE-2018-5188: firefox - Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. ...
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
Scope:
debian
CVE-2026-5732P3HIGHCVSS 8.8fixed in firefox 149.0.2-1 (sid)2026
CVE-2026-5732 [HIGH] CVE-2026-5732: firefox - Incorrect boundary conditions, integer overflow in the Graphics: Text component....
Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability affects Firefox < 149.0.2, Firefox ESR < 140.9.1, Thunderbird < 149.0.2, and Thunderbird < 140.9.1.
Scope: local
sid: resolved (fixed in 149.0.2-1)
debian