Debian Firefox-Esr vulnerabilities

1,071 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
1,071
CISA KEV
11
actively exploited
Public exploits
23
Exploited in wild
15
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW125

Vulnerabilities

Page 33 of 54
CVE-2019-9820CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-9820 [CRITICAL] CVE-2019-9820: firefox - A use-after-free vulnerability can occur in the chrome event handler when it is ... A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2019-9819CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-9819 [CRITICAL] CVE-2019-9819: firefox - A vulnerability where a JavaScript compartment mismatch can occur while working ... A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2019-9796CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9796 [CRITICAL] CVE-2019-9796: firefox - A use-after-free vulnerability can occur when the SMIL animation controller inco... A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the driver's observer array. This vulnerabil
debian
CVE-2019-9800CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-9800 [CRITICAL] CVE-2019-9800: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR <
debian
CVE-2019-9788CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9788 [CRITICAL] CVE-2019-9788: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox
debian
CVE-2019-9795CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9795 [CRITICAL] CVE-2019-9795: firefox - A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compile... A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66. Scope: local sid: resolved (fixed in 66.0-1)
debian
CVE-2019-11692CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11692 [CRITICAL] CVE-2019-11692: firefox - A use-after-free vulnerability can occur when listeners are removed from the eve... A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2019-9792CRITICALCVSS 9.8PoCfixed in firefox 66.0-1 (sid)2019
CVE-2019-9792 [CRITICAL] CVE-2019-9792: firefox - The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT ... The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66. Scope: local sid: res
debian
CVE-2019-11709CRITICALCVSS 9.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11709 [CRITICAL] CVE-2019-11709: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: loc
debian
CVE-2019-17012HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17012 [HIGH] CVE-2019-17012: firefox - Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox... Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed
debian
CVE-2019-17011HIGHCVSS 7.5fixed in firefox 71.0-1 (sid)2019
CVE-2019-17011 [HIGH] CVE-2019-17011: firefox - Under certain conditions, when retrieving a document from a DocShell in the anti... Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-11711HIGHCVSS 8.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11711 [HIGH] CVE-2019-11711: firefox - When an inner window is reused, it does not consider the use of document.domain ... When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerabil
debian
CVE-2019-11757HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11757 [HIGH] CVE-2019-11757: firefox - When following the value's prototype chain, it was possible to retain a referenc... When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2019-17026HIGHCVSS 8.8KEVPoCfixed in firefox 72.0.1-1 (sid)2019
CVE-2019-17026 [HIGH] CVE-2019-17026: firefox - Incorrect alias information in IonMonkey JIT compiler for setting array elements... Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1. Scope: local sid: resolved (fixed in 72.0.1-1)
debian
CVE-2019-17005HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17005 [HIGH] CVE-2019-17005: firefox - The plain text serializer used a fixed-size array for the number of <ol> element... The plain text serializer used a fixed-size array for the number of elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-17024HIGHCVSS 8.8fixed in firefox 72.0-1 (sid)2019
CVE-2019-17024 [HIGH] CVE-2019-17024: firefox - Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox... Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72. Scope: local sid: resolved (fixed in 72.0-1)
debian
CVE-2019-11764HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11764 [HIGH] CVE-2019-11764: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: r
debian
CVE-2019-17010HIGHCVSS 7.5fixed in firefox 71.0-1 (sid)2019
CVE-2019-17010 [HIGH] CVE-2019-17010: firefox - Under certain conditions, when checking the Resist Fingerprinting preference dur... Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-11752HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11752 [HIGH] CVE-2019-11752: firefox - It is possible to delete an IndexedDB key value and subsequently try to extract ... It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1. Scope: local sid: resolved (fixed in 69.0-1)
debian
CVE-2019-9813HIGHCVSS 8.8PoCfixed in firefox 66.0.1-1 (sid)2019
CVE-2019-9813 [HIGH] CVE-2019-9813: firefox - Incorrect handling of __proto__ mutations may lead to type confusion in IonMonke... Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1. Scope: local sid: resolved (fixed in 66.0.1-1)
debian