cbcvebase.

Debian Firefox-Esr vulnerabilities

965 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19

Vulnerabilities

Page 23 of 49
CVE-2017-7752P3HIGHCVSS 8.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7752 [HIGH] CVE-2017-7752: firefox - A use-after-free vulnerability during specific user interactions with the input ... A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. Scope: local sid: resolved (fixe
debian
CVE-2019-17012P3HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17012 [HIGH] CVE-2019-17012: firefox - Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox... Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed
debian
CVE-2020-12420P3HIGHCVSS 8.8fixed in firefox 78.0-1 (sid)2020
CVE-2020-12420 [HIGH] CVE-2020-12420: firefox - When trying to connect to a STUN server, a race condition could have caused a us... When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0. Scope: local sid: resolved (fixed in 78.0-1)
debian
CVE-2019-11746P3HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11746 [HIGH] CVE-2019-11746: firefox - A use-after-free vulnerability can occur while manipulating video elements if th... A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1. Scope: local sid: resolved (fixed in 69.0-1)
debian
CVE-2019-11711P3HIGHCVSS 8.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11711 [HIGH] CVE-2019-11711: firefox - When an inner window is reused, it does not consider the use of document.domain ... When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerabil
debian
CVE-2019-11764P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11764 [HIGH] CVE-2019-11764: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: r
debian
CVE-2021-29970P3HIGHCVSS 8.8fixed in firefox 90.0-1 (sid)2021
CVE-2021-29970 [HIGH] CVE-2021-29970: firefox - A malicious webpage could have triggered a use-after-free, memory corruption, an... A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when accessibility was enabled.*. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90. Scope: local sid: resolved (fixed in 90.0-1)
debian
CVE-2021-29988P3HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29988 [HIGH] CVE-2021-29988: firefox - Firefox incorrectly treated an inline list-item element as a block element, resu... Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91. Scope: local sid: resolved (fixed in 91.0-1)
debian
CVE-2019-11757P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11757 [HIGH] CVE-2019-11757: firefox - When following the value's prototype chain, it was possible to retain a referenc... When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2020-26959P3HIGHCVSS 8.8fixed in firefox 83.0-1 (sid)2020
CVE-2020-26959 [HIGH] CVE-2020-26959: firefox - During browser shutdown, reference decrementing could have occured on a previous... During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. Scope: local sid: resolved (fixed in 83.0-1)
debian
CVE-2018-5095P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5095 [CRITICAL] CVE-2018-5095: firefox - An integer overflow vulnerability in the Skia library when allocating memory for... An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. Scope: local sid: resolved (fixed in 58.0-1)
debian
CVE-2023-29539P3HIGHCVSS 8.8fixed in firefox 112.0-1 (sid)2023
CVE-2023-29539 [HIGH] CVE-2023-29539: firefox - When handling the filename directive in the Content-Disposition header, the file... When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, an
debian
CVE-2023-25746P3HIGHCVSS 8.8fixed in firefox-esr 102.8.0esr-1 (bookworm)2023
CVE-2023-25746 [HIGH] CVE-2023-25746: firefox-esr - Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evide... Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.8 and Firefox ESR < 102.8. Scope: local bookworm: resolved (fixed in 102.8.0esr-1) bullseye: resolved (fixed in
debian
CVE-2022-31740P3HIGHCVSS 8.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31740 [HIGH] CVE-2022-31740: firefox - On arm64, WASM code could have resulted in incorrect assembly generation leading... On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope: local sid: resolved (fixed in 101.0-1)
debian
CVE-2017-5396P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5396 [CRITICAL] CVE-2017-5396: firefox - A use-after-free vulnerability in the Media Decoder when working with media file... A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. Scope: local sid: resolved (fixed in 51.0-1)
debian
CVE-2016-5276P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5276 [CRITICAL] CVE-2016-5276: firefox - Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalid... Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an aria-owns attribute. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2025-1014P3HIGHCVSS 8.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1014 [HIGH] CVE-2025-1014: firefox - Certificate length was not properly checked when added to a certificate store. I... Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135. Scope: local sid: resolved (fixed in 135.0-1)
debian
CVE-2017-5398P3CRITICALCVSS 9.8fixed in firefox 52.0-1 (sid)2017
CVE-2017-5398 [CRITICAL] CVE-2017-5398: firefox - Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed ... Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. Scope: local sid: resolved (fixed in 52.0-1)
debian
CVE-2018-5155P3CRITICALCVSS 9.8fixed in firefox 60.0-1 (sid)2018
CVE-2018-5155 [CRITICAL] CVE-2018-5155: firefox - A use-after-free vulnerability can occur while adjusting layout during SVG anima... A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8. Scope: local sid: resolved (fixed in 60.0-1)
debian
CVE-2017-7819P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7819 [CRITICAL] CVE-2017-7819: firefox - A use-after-free vulnerability can occur in design mode when image objects are r... A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4. Scope: local sid: resolved (fixed in 56.0-1)
debian
Debian Firefox-Esr vulnerabilities | cvebase