Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 27 of 49
CVE-2025-8030P3HIGHCVSS 8.1fixed in firefox 141.0-1 (sid)2025
CVE-2025-8030 [HIGH] CVE-2025-8030: firefox - Insufficient escaping in the “Copy as cURL” feature could potentially be used to...
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Scope: local
sid: resolved (fixed in 141.0-1)
debian
CVE-2017-5386P3HIGHCVSS 7.3fixed in firefox 51.0-1 (sid)2017
CVE-2017-5386 [HIGH] CVE-2017-5386: firefox - WebExtension scripts can use the "data:" protocol to affect pages loaded by othe...
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2026-0878P3HIGHCVSS 8.0fixed in firefox 147.0-1 (sid)2026
CVE-2026-0878 [HIGH] CVE-2026-0878: firefox - Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL...
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
Scope: local
sid: resolved (fixed in 147.0-1)
debian
CVE-2017-7758P3CRITICALCVSS 9.1fixed in firefox 54.0-1 (sid)2017
CVE-2017-7758 [CRITICAL] CVE-2017-7758: firefox - An out-of-bounds read vulnerability with the Opus encoder when the number of cha...
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2024-3857P3HIGHCVSS 7.8fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3857 [HIGH] CVE-2024-3857: firefox - The JIT created incorrect code for arguments in certain cases. This led to poten...
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Scope: local
sid: resolved (fixed in 125.0.1-1)
debian
CVE-2024-5702P3HIGHCVSS 7.5fixed in firefox-esr 115.12.0esr-1~deb12u1 (bookworm)2024
CVE-2024-5702 [HIGH] CVE-2024-5702: firefox-esr - Memory corruption in the networking stack could have led to a potentially exploi...
Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
bookworm: resolved (fixed in 115.12.0esr-1~deb12u1)
bullseye: resolved (fixed in 115.12.0esr-1~deb11u1)
forky: resolved (fixed in 115.12.0esr-1)
sid: resolved (fixed in 1
debian
CVE-2022-38476P3HIGHCVSS 7.5fixed in firefox-esr 102.2.0esr-1 (bookworm)2022
CVE-2022-38476 [HIGH] CVE-2022-38476: firefox-esr - A data race could occur in the <code>PK11_ChangePW</code> function, potentially ...
A data race could occur in the PK11_ChangePW function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
Scope: local
bookworm: resolved (fixed in 102.2.0esr-1)
bullseye: resolved
forky: resolved (fixed
debian
CVE-2026-4694P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4694 [HIGH] CVE-2026-4694: firefox - Incorrect boundary conditions, integer overflow in the Graphics component. This ...
Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4697P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4697 [HIGH] CVE-2026-4697: firefox - Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vul...
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4695P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4695 [HIGH] CVE-2026-4695: firefox - Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vul...
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2024-1552P3HIGHCVSS 7.5fixed in firefox 123.0-1 (sid)2024
CVE-2024-1552 [HIGH] CVE-2024-1552: firefox - Incorrect code generation could have led to unexpected numeric conversions and p...
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Scope: local
sid: resolved (fixed in 123.0-1)
debian
CVE-2022-26387P3HIGHCVSS 7.5fixed in firefox 98.0-1 (sid)2022
CVE-2022-26387 [HIGH] CVE-2022-26387: firefox - When installing an add-on, Firefox verified the signature before prompting the u...
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
Scope: local
sid: resolved (fixed in 98.0-1)
debian
CVE-2022-22741P3HIGHCVSS 7.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22741 [HIGH] CVE-2022-22741: firefox - When resizing a popup while requesting fullscreen access, the popup would have b...
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved (fixed in 96.0-1)
debian
CVE-2023-4051P3HIGHCVSS 7.5fixed in firefox 116.0-1 (sid)2023
CVE-2023-4051 [HIGH] CVE-2023-4051: firefox - A website could have obscured the full screen notification by using the file ope...
A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.
Scope: local
sid: resolved (fixed in 116.0-1)
debian
CVE-2024-8383P3HIGHCVSS 7.5fixed in firefox 130.0-1 (sid)2024
CVE-2024-8383 [HIGH] CVE-2024-8383: firefox - Firefox normally asks for confirmation before asking the operating system to fin...
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could r
debian
CVE-2016-1953P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1953 [HIGH] CVE-2016-1953: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-5264P3HIGHCVSS 8.8fixed in firefox 48.0-1 (sid)2016
CVE-2016-5264 [HIGH] CVE-2016-5264: firefox - Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange ...
Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG element that is mishandled during effect application.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2025-1012P3HIGHCVSS 7.5fixed in firefox 135.0-1 (sid)2025
CVE-2025-1012 [HIGH] CVE-2025-1012: firefox - A race during concurrent delazification could have led to a use-after-free. This...
A race during concurrent delazification could have led to a use-after-free. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Scope: local
sid: resolved (fixed in 135.0-1)
debian
CVE-2026-4714P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4714 [HIGH] CVE-2026-4714: firefox - Incorrect boundary conditions in the Audio/Video component. This vulnerability a...
Incorrect boundary conditions in the Audio/Video component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4708P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4708 [HIGH] CVE-2026-4708: firefox - Incorrect boundary conditions in the Graphics component. This vulnerability affe...
Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian