cbcvebase.

Debian Firefox-Esr vulnerabilities

965 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19

Vulnerabilities

Page 18 of 49
CVE-2017-5433P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5433 [CRITICAL] CVE-2017-5433: firefox - A use-after-free vulnerability in SMIL animation functions occurs when pointers ... A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. Scope: local sid: resolved (fixed in
debian
CVE-2017-5439P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5439 [CRITICAL] CVE-2017-5439: firefox - A use-after-free vulnerability during XSLT processing due to poor handling of te... A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. Scope: local sid: resolved (fixed in 52.0.1-1)
debian
CVE-2017-7784P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7784 [CRITICAL] CVE-2017-7784: firefox - A use-after-free vulnerability can occur when reading an image observer during f... A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. Scope: local sid: resolved (fixed in 55.0-1)
debian
CVE-2016-9898P3CRITICALCVSS 9.8fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9898 [CRITICAL] CVE-2016-9898: firefox - Use-after-free resulting in potentially exploitable crash when manipulating DOM ... Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. Scope: local sid: resolved (fixed in 50.1.0-1)
debian
CVE-2017-5429P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5429 [CRITICAL] CVE-2017-5429: firefox - Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52... Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. Sco
debian
CVE-2018-12378P3CRITICALCVSS 9.8fixed in firefox 62.0-1 (sid)2018
CVE-2018-12378 [CRITICAL] CVE-2018-12378: firefox - A use-after-free vulnerability can occur when an IndexedDB index is deleted whil... A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1. Scope: local sid: resolved (fixed in 62.0-1)
debian
CVE-2018-12377P3CRITICALCVSS 9.8fixed in firefox 62.0-1 (sid)2018
CVE-2018-12377 [CRITICAL] CVE-2018-12377: firefox - A use-after-free vulnerability can occur when refresh driver timers are refreshe... A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1. Scope: local sid: resolved (fixed in 62.0-1)
debian
CVE-2017-7792P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7792 [CRITICAL] CVE-2017-7792: firefox - A buffer overflow will occur when viewing a certificate in the certificate manag... A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. Scope: local sid: resolved (fixed in 55.0-1)
debian
CVE-2017-5380P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5380 [CRITICAL] CVE-2017-5380: firefox - A potential use-after-free found through fuzzing during DOM manipulation of SVG ... A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. Scope: local sid: resolved (fixed in 51.0-1)
debian
CVE-2018-5098P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5098 [CRITICAL] CVE-2018-5098: firefox - A use-after-free vulnerability can occur when form input elements, focus, and se... A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. Scope: local sid: resolved (fixed in 58.0-1)
debian
CVE-2018-12395P3HIGHCVSS 7.5fixed in firefox 63.0-1 (sid)2018
CVE-2018-12395 [HIGH] CVE-2018-12395: firefox - By rewriting the Host: request headers using the webRequest API, a WebExtension ... By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63. Scope: local sid: resolved (fixed in 63.0-1)
debian
CVE-2017-7800P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7800 [CRITICAL] CVE-2017-7800: firefox - A use-after-free vulnerability can occur in WebSockets when the object holding t... A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. Scope: local sid: resolved (fixed in 55.0-1)
debian
CVE-2017-7749P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7749 [CRITICAL] CVE-2017-7749: firefox - A use-after-free vulnerability when using an incorrect URL during the reloading ... A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. Scope: local sid: resolved (fixed in 54.0-1)
debian
CVE-2020-12395P3CRITICALCVSS 9.8fixed in firefox 76.0-1 (sid)2020
CVE-2020-12395 [CRITICAL] CVE-2020-12395: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. Scope:
debian
CVE-2019-9788P3CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9788 [CRITICAL] CVE-2019-9788: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox
debian
CVE-2026-0877P3HIGHCVSS 8.1fixed in firefox 147.0-1 (sid)2026
CVE-2026-0877 [HIGH] CVE-2026-0877: firefox - Mitigation bypass in the DOM: Security component. This vulnerability affects Fir... Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7. Scope: local sid: resolved (fixed in 147.0-1)
debian
CVE-2026-4718P3HIGHCVSS 8.1fixed in firefox 149.0-1 (sid)2026
CVE-2026-4718 [HIGH] CVE-2026-4718: firefox - Undefined behavior in the WebRTC: Signaling component. This vulnerability affect... Undefined behavior in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2025-13018P3HIGHCVSS 8.1fixed in firefox 145.0-1 (sid)2025
CVE-2025-13018 [HIGH] CVE-2025-13018: firefox - Mitigation bypass in the DOM: Security component. This vulnerability affects Fir... Mitigation bypass in the DOM: Security component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5. Scope: local sid: resolved (fixed in 145.0-1)
debian
CVE-2019-9800P3CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-9800 [CRITICAL] CVE-2019-9800: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR <
debian
CVE-2019-11691P3CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11691 [CRITICAL] CVE-2019-11691: firefox - A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) ... A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
Debian Firefox-Esr vulnerabilities | cvebase