cbcvebase.

Debian Firefox-Esr vulnerabilities

965 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19

Vulnerabilities

Page 26 of 49
CVE-2017-7773P3HIGHCVSS 8.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7773 [HIGH] CVE-2017-7773: firefox - Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz... Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. Scope: local sid: resolved (fixed in 54.0-1)
debian
CVE-2021-29980P3HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29980 [HIGH] CVE-2021-29980: firefox - Uninitialized memory in a canvas object could have caused an incorrect free() le... Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91. Scope: local sid: resolved (fixed in 91.0-1)
debian
CVE-2022-22738P3HIGHCVSS 8.8fixed in firefox 96.0-1 (sid)2022
CVE-2022-22738 [HIGH] CVE-2022-22738: firefox - Applying a CSS filter effect could have accessed out of bounds memory. This coul... Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2022-34468P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34468 [HIGH] CVE-2022-34468: firefox - An iframe that was not permitted to run scripts could do so if the user clicked ... An iframe that was not permitted to run scripts could do so if the user clicked on a javascript: link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11. Scope: local sid: resolved (fixed in 102.0-1)
debian
CVE-2022-46871P3HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46871 [HIGH] CVE-2022-46871: firefox - An out of date library (libusrsctp) contained vulnerabilities that could potenti... An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108. Scope: local sid: resolved (fixed in 108.0-1)
debian
CVE-2022-29909P3HIGHCVSS 8.8fixed in firefox 100.0-1 (sid)2022
CVE-2022-29909 [HIGH] CVE-2022-29909: firefox - Documents in deeply-nested cross-origin browsing contexts could have obtained pe... Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. Scope: local sid: resolved (fixed in 100.0-1)
debian
CVE-2022-45412P3HIGHCVSS 8.8fixed in firefox 107.0-1 (sid)2022
CVE-2022-45412 [HIGH] CVE-2022-45412: firefox - When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error m... When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. *This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and F
debian
CVE-2022-34481P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34481 [HIGH] CVE-2022-34481: firefox - In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer over... In the nsTArray_Impl::ReplaceElementsAt() function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11. Scope: local sid: resolved (fixed in 102.0-1)
debian
CVE-2023-32213P3HIGHCVSS 8.8fixed in firefox 113.0-1 (sid)2023
CVE-2023-32213 [HIGH] CVE-2023-32213: firefox - When reading a file, an uninitialized value could have been used as read limit. ... When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. Scope: local sid: resolved (fixed in 113.0-1)
debian
CVE-2016-5257P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5257 [CRITICAL] CVE-2016-5257: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be... Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2022-46881P3HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-46881 [HIGH] CVE-2022-46881: firefox - An optimization in WebGL was incorrect in some cases, and could have led to memo... An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106, Firefox ESR < 102.6, and Th
debian
CVE-2022-31741P3HIGHCVSS 8.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31741 [HIGH] CVE-2022-31741: firefox - A crafted CMS message could have been processed incorrectly, leading to an inval... A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope: local sid: resolved (fixed in 101.0-1)
debian
CVE-2016-5277P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5277 [CRITICAL] CVE-2016-5277: firefox - Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Fi... Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation. S
debian
CVE-2017-5373P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5373 [CRITICAL] CVE-2017-5373: firefox - Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of t... Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. Scope: local sid: resolved (fixed in 51.0-1)
debian
CVE-2016-5290P3CRITICALCVSS 9.8fixed in firefox 50.0-1 (sid)2016
CVE-2016-5290 [CRITICAL] CVE-2016-5290: firefox - Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of the... Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50. Scope: local sid: resolved (fixed in 50.0-1)
debian
CVE-2018-5183P3CRITICALCVSS 9.8fixed in firefox-esr 52.8.0esr-1 (bookworm)2018
CVE-2018-5183 [CRITICAL] CVE-2018-5183: firefox-esr - Mozilla developers backported selected changes in the Skia library. These change... Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8. Scope: local bookworm: resolved (fixed in 52.8.0esr-1) bullseye: resolved (fixed in
debian
CVE-2017-5440P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5440 [CRITICAL] CVE-2017-5440: firefox - A use-after-free vulnerability during XSLT processing due to a failure to propag... A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. Scope: local
debian
CVE-2018-5145P3CRITICALCVSS 9.8fixed in firefox-esr 52.7.0esr-1 (bookworm)2018
CVE-2018-5145 [CRITICAL] CVE-2018-5145: firefox-esr - Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence... Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7. Scope: local bookworm: resolved (fixed in 52.7.0esr-1) bullseye: resolved (fixed in 52.7.0
debian
CVE-2017-7810P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7810 [CRITICAL] CVE-2017-7810: firefox - Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of the... Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4. Scope: local sid: resolved (fixed in 56.0-1)
debian
CVE-2017-7809P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7809 [CRITICAL] CVE-2017-7809: firefox - A use-after-free vulnerability can occur when an editor DOM node is deleted prem... A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. Scope: local sid: resolved (fixed in 55.0-1)
debian
Debian Firefox-Esr vulnerabilities | cvebase