Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 20 of 49
CVE-2021-29967P3HIGHCVSS 8.8fixed in firefox 89.0-1 (sid)2021
CVE-2021-29967 [HIGH] CVE-2021-29967: firefox - Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
Scope: local
sid: resolved (fix
debian
CVE-2020-6805P3HIGHCVSS 8.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6805 [HIGH] CVE-2020-6805: firefox - When removing data about an origin whose tab was recently closed, a use-after-fr...
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Scope: local
sid: resolved (fixed in 74.0-1)
debian
CVE-2020-6807P3HIGHCVSS 8.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6807 [HIGH] CVE-2020-6807: firefox - When a device was changed while a stream was about to be destroyed, the <code>st...
When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Scope: local
sid: resolved (fixed in 74.0-1)
debian
CVE-2021-38501P3HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-38501 [HIGH] CVE-2021-38501: firefox - Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
Scope: local
sid: resolved (fixed
debian
CVE-2022-34484P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34484 [HIGH] CVE-2022-34484: firefox - The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbi...
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Scope: local
debian
CVE-2022-42928P3HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-42928 [HIGH] CVE-2022-42928: firefox - Certain types of allocations were missing annotations that, if the Garbage Colle...
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Scope: local
sid: resolved (fixed in 106.0-1)
debian
CVE-2023-25732P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25732 [HIGH] CVE-2023-25732: firefox - When encoding data from an <code>inputStream</code> in <code>xpcom</code> the si...
When encoding data from an inputStream in xpcom the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2022-46878P3HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46878 [HIGH] CVE-2022-46878: firefox - Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fu...
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firefox ESR < 102.6
debian
CVE-2023-25735P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25735 [HIGH] CVE-2023-25735: firefox - Cross-compartment wrappers wrapping a scripted proxy could have caused objects f...
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2022-45421P3HIGHCVSS 8.8fixed in firefox 107.0-1 (sid)2022
CVE-2022-45421 [HIGH] CVE-2022-45421: firefox - Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety b...
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Scope: l
debian
CVE-2022-28289P3HIGHCVSS 8.8fixed in firefox 99.0-1 (sid)2022
CVE-2022-28289 [HIGH] CVE-2022-28289: firefox - Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriel...
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunder
debian
CVE-2017-7785P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7785 [CRITICAL] CVE-2017-7785: firefox - A buffer overflow can occur when manipulating Accessible Rich Internet Applicati...
A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2018-12393P3HIGHCVSS 7.5fixed in firefox 63.0-1 (sid)2018
CVE-2018-12393 [HIGH] CVE-2018-12393: firefox - A potential vulnerability was found in 32-bit builds where an integer overflow d...
A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox < 63, Firefox E
debian
CVE-2022-22763P3HIGHCVSS 8.8fixed in firefox-esr 91.6.0esr-1 (bookworm)2022
CVE-2022-22763 [HIGH] CVE-2022-22763: firefox-esr - When a worker is shutdown, it was possible to cause script to run late in the li...
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.
Scope: local
bookworm: resolved (fixed in 91.6.0esr-1)
bullseye: resolved (fixed in 91.6.0esr-1~deb11u1)
forky: resolved (fixed in 91.6.0esr
debian
CVE-2016-5256P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5256 [CRITICAL] CVE-2016-5256: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2017-5400P3CRITICALCVSS 9.8fixed in firefox 52.0-1 (sid)2017
CVE-2017-5400 [CRITICAL] CVE-2017-5400: firefox - JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASL...
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Scope: local
sid: resolved (fixed in 52.0-1)
debian
CVE-2018-18501P3CRITICALCVSS 9.8fixed in firefox 65.0-1 (sid)2018
CVE-2018-18501 [CRITICAL] CVE-2018-18501: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
Scope: loc
debian
CVE-2018-5154P3CRITICALCVSS 9.8fixed in firefox 60.0-1 (sid)2018
CVE-2018-5154 [CRITICAL] CVE-2018-5154: firefox - A use-after-free vulnerability can occur while enumerating attributes during SVG...
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
Scope: local
sid: resolved (fixed in 60.0-1)
debian
CVE-2017-5376P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5376 [CRITICAL] CVE-2017-5376: firefox - Use-after-free while manipulating XSL in XSLT documents. This vulnerability affe...
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2018-12390P3CRITICALCVSS 9.8fixed in firefox 63.0-1 (sid)2018
CVE-2018-12390 [CRITICAL] CVE-2018-12390: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
Scope: loc
debian