Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 28 of 49
CVE-2026-4719P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4719 [HIGH] CVE-2026-4719: firefox - Incorrect boundary conditions in the Graphics: Text component. This vulnerabilit...
Incorrect boundary conditions in the Graphics: Text component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4713P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4713 [HIGH] CVE-2026-4713: firefox - Incorrect boundary conditions in the Graphics component. This vulnerability affe...
Incorrect boundary conditions in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4704P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4704 [HIGH] CVE-2026-4704: firefox - Denial-of-service in the WebRTC: Signaling component. This vulnerability affects...
Denial-of-service in the WebRTC: Signaling component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2022-22759P3CRITICALCVSS 9.6fixed in firefox 97.0-1 (sid)2022
CVE-2022-22759 [CRITICAL] CVE-2022-22759: firefox - If a document created a sandboxed iframe without <code>allow-scripts</code>, and...
If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Scope: local
sid: resolved (fixed in 97.0-1)
debian
CVE-2025-1936P3HIGHCVSS 7.3fixed in firefox 136.0-1 (sid)2025
CVE-2025-1936 [HIGH] CVE-2025-1936: firefox - jar: URLs retrieve local file content packaged in a ZIP archive. The null and ev...
jar: URLs retrieve local file content packaged in a ZIP archive. The null and everything after it was ignored when retrieving the content from the archive, but the fake extension after the null was used to determine the type of content. This could have been used to hide code in a web extension disguised as something else like an image. This vulnerability affects Firef
debian
CVE-2025-10528P3HIGHCVSS 7.3fixed in firefox 143.0-1 (sid)2025
CVE-2025-10528 [HIGH] CVE-2025-10528: firefox - Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canva...
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2018-5125P3HIGHCVSS 8.8fixed in firefox 59.0-1 (sid)2018
CVE-2018-5125 [HIGH] CVE-2018-5125: firefox - Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of the...
Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
Scope: local
sid: resolved (fixed in 59.0-1)
debian
CVE-2016-2795P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2795 [HIGH] CVE-2016-2795: firefox - The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as us...
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (
debian
CVE-2016-2790P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2790 [HIGH] CVE-2016-2790: firefox - The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as use...
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (f
debian
CVE-2020-6796P3HIGHCVSS 8.8fixed in firefox 73.0-1 (sid)2020
CVE-2020-6796 [HIGH] CVE-2020-6796: firefox - A content process could have modified shared memory relating to crash reporting ...
A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 73 and Firefox < ESR68.5.
Scope: local
sid: resolved (fixed in 73.0-1)
debian
CVE-2021-38504P3HIGHCVSS 8.8fixed in firefox 94.0-1 (sid)2021
CVE-2021-38504 [HIGH] CVE-2021-38504: firefox - When interacting with an HTML input element's file picker dialog with webkitdire...
When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
sid: resolved (fixed in 94.0-1)
debian
CVE-2016-5283P3HIGHCVSS 8.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5283 [HIGH] CVE-2016-5283: firefox - Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Po...
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2019-11760P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11760 [HIGH] CVE-2019-11760: firefox - A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling...
A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
Scope: local
sid: resolved (fixed in 70.0-1)
debian
CVE-2019-11735P3HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11735 [HIGH] CVE-2019-11735: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
Scope: local
sid: resolved (fixed in
debian
CVE-2021-29946P3HIGHCVSS 8.8fixed in firefox 88.0-1 (sid)2021
CVE-2021-29946 [HIGH] CVE-2021-29946: firefox - Ports that were written as an integer overflow above the bounds of a 16-bit inte...
Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2016-5297P3CRITICALCVSS 9.8fixed in firefox 50.0-1 (sid)2016
CVE-2016-5297 [CRITICAL] CVE-2016-5297: firefox - An error in argument length checking in JavaScript, leading to potential integer...
An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2017-5378P3HIGHCVSS 7.5fixed in firefox 51.0-1 (sid)2017
CVE-2017-5378 [HIGH] CVE-2017-5378: firefox - Hashed codes of JavaScript objects are shared between pages. This allows for poi...
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2017-7757P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7757 [CRITICAL] CVE-2017-7757: firefox - A use-after-free vulnerability in IndexedDB when one of its objects is destroyed...
A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2017-5470P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-5470 [CRITICAL] CVE-2017-5470: firefox - Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of the...
Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2019-11719P3LOWCVSS 7.5fixed in firefox 68.0-1 (sid)2019
CVE-2019-11719 [HIGH] CVE-2019-11719: firefox - When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes,...
When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian