Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 19 of 49
CVE-2025-59375P3HIGHCVSS 7.5fixed in expat 2.7.2-1 (forky)2025
CVE-2025-59375 [HIGH] CVE-2025-59375: expat - libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory ...
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.2-1)
sid: resolved (fixed in 2.7.2-1)
trixie: open
debian
CVE-2006-6504P3HIGHCVSS 9.3fixed in firefox 45.0-1 (sid)2006
CVE-2006-6504 [CRITICAL] CVE-2006-6504: firefox - Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1...
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2796P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2796 [HIGH] CVE-2016-2796: firefox - Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in...
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2017-5444P3HIGHCVSS 7.5fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5444 [HIGH] CVE-2017-5444: firefox - A buffer overflow vulnerability while parsing "application/http-index-format" fo...
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2021-4129P3CRITICALCVSS 9.8fixed in firefox 95.0-1 (sid)2021
CVE-2021-4129 [CRITICAL] CVE-2021-4129: firefox - Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele ...
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability
debian
CVE-2022-29917P3CRITICALCVSS 9.8fixed in firefox 100.0-1 (sid)2022
CVE-2022-29917 [CRITICAL] CVE-2022-29917: firefox - Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla...
Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird <
debian
CVE-2024-11704P3CRITICALCVSS 9.8fixed in firefox 134.0-1 (sid)2024
CVE-2024-11704 [CRITICAL] CVE-2024-11704: firefox - A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` w...
A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.
Scope: local
sid: resolved (
debian
CVE-2024-6604P3HIGHCVSS 7.5fixed in firefox 128.0-1 (sid)2024
CVE-2024-6604 [HIGH] CVE-2024-6604: firefox - Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 1...
Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Scope: local
sid
debian
CVE-2025-1937P3HIGHCVSS 7.5fixed in firefox 136.0-1 (sid)2025
CVE-2025-1937 [HIGH] CVE-2025-1937: firefox - Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, ...
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thund
debian
CVE-2016-9066P3HIGHCVSS 7.5fixed in firefox 50.0-1 (sid)2016
CVE-2016-9066 [HIGH] CVE-2016-9066: firefox - A buffer overflow resulting in a potentially exploitable crash due to memory all...
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2018-12363P3HIGHCVSS 8.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-12363 [HIGH] CVE-2018-12363: firefox - A use-after-free vulnerability can occur when script uses mutation events to mov...
A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a pointer referencing it. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ES
debian
CVE-2016-1959P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1959 [HIGH] CVE-2016-1959: firefox - The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote atta...
The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2006-5633P4LOWCVSS 5.0PoCfixed in firefox 45.0-1 (sid)2006
CVE-2006-5633 [MEDIUM] CVE-2006-5633: firefox - Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a ...
Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was poss
debian
CVE-2020-6800P3HIGHCVSS 8.8fixed in firefox 73.0-1 (sid)2020
CVE-2020-6800 [HIGH] CVE-2020-6800: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product because script
debian
CVE-2016-1951P3HIGHCVSS 8.6fixed in firefox 45.0-1 (sid)2016
CVE-2016-1951 [HIGH] CVE-2016-1951: firefox - Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (N...
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2019-11740P3HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11740 [HIGH] CVE-2019-11740: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firef
debian
CVE-2021-38496P3HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-38496 [HIGH] CVE-2021-38496: firefox - During operations on MessageTasks, a task may have been removed while it was sti...
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
Scope: local
sid: resolved (fixed in 93.0-1)
debian
CVE-2020-12410P3HIGHCVSS 8.8fixed in firefox 77.0-1 (sid)2020
CVE-2020-12410 [HIGH] CVE-2020-12410: firefox - Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Scope: local
sid: resolved (fixe
debian
CVE-2021-29985P3HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29985 [HIGH] CVE-2021-29985: firefox - A use-after-free vulnerability in media channels could have led to memory corrup...
A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Scope: local
sid: resolved (fixed in 91.0-1)
debian
CVE-2021-29984P3HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29984 [HIGH] CVE-2021-29984: firefox - Instruction reordering resulted in a sequence of instructions that would cause a...
Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Scope: local
sid: resolved (fixed in 91.0-1)
debian