Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 32 of 49
CVE-2017-5379P3HIGHCVSS 7.5fixed in firefox 51.0-1 (sid)2017
CVE-2017-5379 [HIGH] CVE-2017-5379: firefox - Use-after-free vulnerability in Web Animations when interacting with cycle colle...
Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2006-2723P4LOWCVSS 5.0PoCfixed in firefox 45.0-1 (sid)2006
CVE-2006-2723 [MEDIUM] CVE-2006-2723: firefox - Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial...
Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags. NOTE: a followup post indicated that the initial report could not be verified.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2017-5382P3HIGHCVSS 7.5fixed in firefox 51.0-1 (sid)2017
CVE-2017-5382 [HIGH] CVE-2017-5382: firefox - Feed preview for RSS feeds can be used to capture errors and exceptions generate...
Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal information not meant to be seen by web content. This vulnerability affects Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2016-9902P3HIGHCVSS 7.5fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9902 [HIGH] CVE-2016-9902: firefox - The Pocket toolbar button, once activated, listens for events fired from it's ow...
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50
debian
CVE-2017-5381P3HIGHCVSS 7.5fixed in firefox 51.0-1 (sid)2017
CVE-2017-5381 [HIGH] CVE-2017-5381: firefox - The "export" function in the Certificate Viewer can force local filesystem navig...
The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowing certificate content to be saved in unsafe locations with an arbitrary filename. This vulnerability affects Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2021-23961P3HIGHCVSS 7.4fixed in firefox 85.0-1 (sid)2021
CVE-2021-23961 [HIGH] CVE-2021-23961: firefox - Further techniques that built on the slipstream research combined with a malicio...
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.
Scope: local
sid: resolved (fixed in 85.0-1)
debian
CVE-2023-37208P3HIGHCVSS 7.8fixed in firefox 115.0-1 (sid)2023
CVE-2023-37208 [HIGH] CVE-2023-37208: firefox - When opening Diagcab files, Firefox did not warn the user that these files may c...
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Scope: local
sid: resolved (fixed in 115.0-1)
debian
CVE-2016-1952P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1952 [HIGH] CVE-2016-1952: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2793P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2793 [HIGH] CVE-2016-2793: firefox - CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45....
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2798P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2798 [HIGH] CVE-2016-2798: firefox - The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, a...
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2802P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2802 [HIGH] CVE-2016-2802: firefox - The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before...
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2791P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2791 [HIGH] CVE-2016-2791: firefox - The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in...
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-1969P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1969 [HIGH] CVE-2016-1969: firefox - The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox befo...
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-5296P3HIGHCVSS 7.5fixed in firefox 50.0-1 (sid)2016
CVE-2016-5296 [HIGH] CVE-2016-5296: firefox - A heap-buffer-overflow in Cairo when processing SVG content caused by compiler o...
A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2016-9070P3HIGHCVSS 8.0fixed in firefox 50.0-1 (sid)2016
CVE-2016-9070 [HIGH] CVE-2016-9070: firefox - A maliciously crafted page loaded to the sidebar through a bookmark can referenc...
A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operations violating cross-origin protections. This vulnerability affects Firefox < 50.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2016-5266P3HIGHCVSS 8.1fixed in firefox 48.0-1 (sid)2016
CVE-2016-5266 [HIGH] CVE-2016-5266: firefox - Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTr...
Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote attackers to access local files via a crafted web site.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2016-2821P3HIGHCVSS 7.5fixed in firefox 47.0-1 (sid)2016
CVE-2016-2821 [HIGH] CVE-2016-2821: firefox - Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firef...
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor.
Scope: local
sid: resolved
debian
CVE-2018-5144P3HIGHCVSS 7.3fixed in firefox-esr 52.7.0esr-1 (bookworm)2018
CVE-2018-5144 [HIGH] CVE-2018-5144: firefox-esr - An integer overflow can occur during conversion of text to some Unicode characte...
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
Scope: local
bookworm: resolved (fixed in 52.7.0esr-1)
bullseye: resolved (fixed in 52.7.0esr-1)
forky: resolved (fixed in 52.7.0esr-1)
sid: resolved (fixed in 52.7.0esr-1
debian
CVE-2017-5445P3HIGHCVSS 7.5fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5445 [HIGH] CVE-2017-5445: firefox - A vulnerability while parsing "application/http-index-format" format content whe...
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2022-42927P3HIGHCVSS 8.1fixed in firefox 106.0-1 (sid)2022
CVE-2022-42927 [HIGH] CVE-2022-42927: firefox - A same-origin policy violation could have allowed the theft of cross-origin URL ...
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
Scope: local
sid: resolved (fixed in 106.0-1)
debian