Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 31 of 49
CVE-2018-5157P3HIGHCVSS 7.5fixed in firefox 60.0-1 (sid)2018
CVE-2018-5157 [HIGH] CVE-2018-5157: firefox - Same-origin protections for the PDF viewer can be bypassed, allowing a malicious...
Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
Scope: local
sid: resolved (fixed in 60.0-1)
debian
CVE-2017-5374P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5374 [CRITICAL] CVE-2017-5374: firefox - Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evid...
Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2021-38498P3HIGHCVSS 7.5fixed in firefox 93.0-1 (sid)2021
CVE-2021-38498 [HIGH] CVE-2021-38498: firefox - During process shutdown, a document could have caused a use-after-free of a lang...
During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
Scope: local
sid: resolved (fixed in 93.0-1)
debian
CVE-2023-5728P3HIGHCVSS 7.5fixed in firefox 119.0-1 (sid)2023
CVE-2023-5728 [HIGH] CVE-2023-5728: firefox - During garbage collection extra operations were performed on a object that shoul...
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Scope: local
sid: resolved (fixed in 119.0-1)
debian
CVE-2022-22737P3HIGHCVSS 7.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22737 [HIGH] CVE-2022-22737: firefox - Constructing audio sinks could have lead to a race condition when playing audio ...
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved (fixed in 96.0-1)
debian
CVE-2016-2794P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2794 [HIGH] CVE-2016-2794: firefox - The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 befor...
The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2024-7652P3HIGHCVSS 7.5fixed in firefox 128.0-1 (sid)2024
CVE-2024-7652 [HIGH] CVE-2024-7652: firefox - An error in the ECMA-262 specification relating to Async Generators could have r...
An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Scope: local
sid: resolved (fixed in 128.0-1)
debian
CVE-2016-2834P3HIGHCVSS 8.8fixed in firefox 47.0-1 (sid)2016
CVE-2016-2834 [HIGH] CVE-2016-2834: firefox - Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox ...
Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
Scope: local
sid: resolved (fixed in 47.0-1)
debian
CVE-2016-2836P3HIGHCVSS 8.8fixed in firefox 48.0-1 (sid)2016
CVE-2016-2836 [HIGH] CVE-2016-2836: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to Http2Session::Shutdown and SpdySession31::Shutdown, and other vectors.
Scope: local
sid: resolv
debian
CVE-2016-2835P3HIGHCVSS 8.8fixed in firefox 48.0-1 (sid)2016
CVE-2016-2835 [HIGH] CVE-2016-2835: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2016-1964P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1964 [HIGH] CVE-2016-1964: firefox - Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox...
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2019-9812P3CRITICALCVSS 9.3fixed in firefox 69.0-1 (sid)2019
CVE-2019-9812 [CRITICAL] CVE-2019-9812: firefox - Given a compromised sandboxed content process due to a separate vulnerability, i...
Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart without the s
debian
CVE-2017-7774P3CRITICALCVSS 9.1fixed in firefox 54.0-1 (sid)2017
CVE-2017-7774 [CRITICAL] CVE-2017-7774: firefox - Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf:...
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2019-11712P3HIGHCVSS 8.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11712 [HIGH] CVE-2019-11712: firefox - POST requests made by NPAPI plugins, such as Flash, that receive a status 308 re...
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian
CVE-2017-7807P3HIGHCVSS 8.1fixed in firefox 55.0-1 (sid)2017
CVE-2017-7807 [HIGH] CVE-2017-7807: firefox - A mechanism that uses AppCache to hijack a URL in a domain using fallback by ser...
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2016-9896P3HIGHCVSS 8.1fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9896 [HIGH] CVE-2016-9896: firefox - Use-after-free while manipulating the "navigator" object within WebVR. Note: Web...
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2016-9904P3HIGHCVSS 7.5fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9904 [HIGH] CVE-2016-9904: firefox - An attacker could use a JavaScript Map/Set timing attack to determine whether an...
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Scope: local
sid: resolved (fixed i
debian
CVE-2017-7754P3HIGHCVSS 7.5fixed in firefox 54.0-1 (sid)2017
CVE-2017-7754 [HIGH] CVE-2017-7754: firefox - An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object dur...
An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2016-2812P3HIGHCVSS 7.5fixed in firefox 46.0-1 (sid)2016
CVE-2016-2812 [HIGH] CVE-2016-2812: firefox - Race condition in the get implementation in the ServiceWorkerManager class in th...
Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site.
Scope: local
sid: resolved (fixed in 46.0-1)
debian
CVE-2017-7803P3HIGHCVSS 7.5fixed in firefox 55.0-1 (sid)2017
CVE-2017-7803 [HIGH] CVE-2017-7803: firefox - When a page's content security policy (CSP) header contains a "sandbox" directiv...
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian