Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 24 of 49
CVE-2018-5089P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5089 [CRITICAL] CVE-2018-5089: firefox - Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of the...
Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2017-7826P3CRITICALCVSS 9.8fixed in firefox 57.0-1 (sid)2017
CVE-2017-7826 [CRITICAL] CVE-2017-7826: firefox - Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of the...
Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
Scope: local
sid: resolved (fixed in 57.0-1)
debian
CVE-2006-4310P4MEDIUMCVSS 4.3PoCfixed in firefox 45.0-1 (sid)2006
CVE-2006-4310 [MEDIUM] CVE-2006-4310: firefox - Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (cr...
Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a username and password via the FTP URI.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2017-7843P3HIGHCVSS 7.5fixed in firefox 57.0.1-1 (sid)2017
CVE-2017-7843 [HIGH] CVE-2017-7843: firefox - When Private Browsing mode is used, it is possible for a web worker to write per...
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and
debian
CVE-2020-12387P3HIGHCVSS 8.1fixed in firefox 76.0-1 (sid)2020
CVE-2020-12387 [HIGH] CVE-2020-12387: firefox - A race condition when running shutdown code for Web Worker led to a use-after-fr...
A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
Scope: local
sid: resolved (fixed in 76.0-1)
debian
CVE-2018-12376P3CRITICALCVSS 9.8fixed in firefox 62.0-1 (sid)2018
CVE-2018-12376 [CRITICAL] CVE-2018-12376: firefox - Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bug...
Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Scope: local
sid: resolved (fixed in 62.0-1)
debian
CVE-2017-5401P3CRITICALCVSS 9.8fixed in firefox 52.0-1 (sid)2017
CVE-2017-5401 [CRITICAL] CVE-2017-5401: firefox - A crash triggerable by web content in which an "ErrorResult" references unassign...
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Scope: local
sid: resolved (fixed in 52.0-1)
debian
CVE-2021-29986P3HIGHCVSS 8.1fixed in firefox 91.0-1 (sid)2021
CVE-2021-29986 [HIGH] CVE-2021-29986: firefox - A suspected race condition when calling getaddrinfo led to memory corruption and...
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Scope: local
sid: resolved (fixed in 91.0-1)
debian
CVE-2017-7751P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7751 [CRITICAL] CVE-2017-7751: firefox - A use-after-free vulnerability with content viewer listeners that results in a p...
A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2017-7779P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7779 [CRITICAL] CVE-2017-7779: firefox - Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbir...
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in
debian
CVE-2017-7801P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7801 [CRITICAL] CVE-2017-7801: firefox - A use-after-free vulnerability can occur while re-computing layout for a "marque...
A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2024-7525P3HIGHCVSS 8.1fixed in firefox 129.0-1 (sid)2024
CVE-2024-7525 [HIGH] CVE-2024-7525: firefox - It was possible for a web extension with minimal permissions to create a `Stream...
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Scope: local
sid: resolved (fixed in 129.0-1)
debian
CVE-2017-7793P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7793 [CRITICAL] CVE-2017-7793: firefox - A use-after-free vulnerability can occur in the Fetch API when the worker or the...
A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Scope: local
sid: resolved (fixed in 56.0-1)
debian
CVE-2016-2804P3HIGHCVSS 8.8fixed in firefox 46.0-1 (sid)2016
CVE-2016-2804 [HIGH] CVE-2016-2804: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved (fixed in 46.0-1)
debian
CVE-2025-9180P3HIGHCVSS 8.1fixed in firefox 142.0-1 (sid)2025
CVE-2025-9180 [HIGH] CVE-2025-9180: firefox - Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerabilit...
Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
Scope: local
sid: resolved (fixed in 142.0-1)
debian
CVE-2020-6814P3CRITICALCVSS 9.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6814 [CRITICAL] CVE-2020-6814: firefox - Mozilla developers reported memory safety bugs present in Firefox and Thunderbir...
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Scope: local
sid
debian
CVE-2017-5377P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5377 [CRITICAL] CVE-2017-5377: firefox - A memory corruption vulnerability in Skia that can occur when using transforms t...
A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2017-7753P3CRITICALCVSS 9.1fixed in firefox 55.0-1 (sid)2017
CVE-2017-7753 [CRITICAL] CVE-2017-7753: firefox - An out-of-bounds read occurs when applying style rules to pseudo-elements, such ...
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2026-4699P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4699 [HIGH] CVE-2026-4699: firefox - Incorrect boundary conditions in the Layout: Text and Fonts component. This vuln...
Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4693P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4693 [HIGH] CVE-2026-4693: firefox - Incorrect boundary conditions in the Audio/Video: Playback component. This vulne...
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian