Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 33 of 49
CVE-2017-5385P3HIGHCVSS 7.5fixed in firefox 51.0-1 (sid)2017
CVE-2017-5385 [HIGH] CVE-2017-5385: firefox - Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME...
Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to potential information disclosure for sites using this header. This vulnerability affects Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2019-17010P3HIGHCVSS 7.5fixed in firefox 71.0-1 (sid)2019
CVE-2019-17010 [HIGH] CVE-2019-17010: firefox - Under certain conditions, when checking the Resist Fingerprinting preference dur...
Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Scope: local
sid: resolved (fixed in 71.0-1)
debian
CVE-2019-17011P3HIGHCVSS 7.5fixed in firefox 71.0-1 (sid)2019
CVE-2019-17011 [HIGH] CVE-2019-17011: firefox - Under certain conditions, when retrieving a document from a DocShell in the anti...
Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Scope: local
sid: resolved (fixed in 71.0-1)
debian
CVE-2020-6821P3HIGHCVSS 7.5fixed in firefox 75.0-1 (sid)2020
CVE-2020-6821 [HIGH] CVE-2020-6821: firefox - When reading from areas partially or fully outside the source resource with WebG...
When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
Scope: local
sid: resolved
debian
CVE-2023-1999P3MEDIUMCVSS 5.3fixed in firefox 112.0-1 (sid)2023
CVE-2023-1999 [MEDIUM] CVE-2023-1999: firefox - There exists a use after free/double free in libwebp. An attacker can use the Ap...
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
Scope: local
s
debian
CVE-2018-12379P3LOWCVSS 7.8fixed in firefox 62.0-1 (sid)2018
CVE-2018-12379 [HIGH] CVE-2018-12379: firefox - When the Mozilla Updater opens a MAR format file which contains a very long item...
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbi
debian
CVE-2023-4048P3HIGHCVSS 7.5fixed in firefox 116.0-1 (sid)2023
CVE-2023-4048 [HIGH] CVE-2023-4048: firefox - An out-of-bounds read could have led to an exploitable crash when parsing HTML w...
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Scope: local
sid: resolved (fixed in 116.0-1)
debian
CVE-2025-1938P3MEDIUMCVSS 6.5fixed in firefox 136.0-1 (sid)2025
CVE-2025-1938 [MEDIUM] CVE-2025-1938: firefox - Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, a...
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
S
debian
CVE-2016-9897P3HIGHCVSS 7.5fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9897 [HIGH] CVE-2016-9897: firefox - Memory corruption resulting in a potentially exploitable crash during WebGL func...
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2019-11729P4LOWCVSS 7.5fixed in firefox 68.0-1 (sid)2019
CVE-2019-11729 [HIGH] CVE-2019-11729: firefox - Empty or malformed p256-ECDH public keys may trigger a segmentation fault due va...
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian
CVE-2021-23981P3HIGHCVSS 8.1fixed in firefox 87.0-1 (sid)2021
CVE-2021-23981 [HIGH] CVE-2021-23981: firefox - A texture upload of a Pixel Buffer Object could have confused the WebGL code to ...
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
Scope: local
sid: resolved (fixed in 87.0-1)
debian
CVE-2016-5284P4HIGHCVSS 7.4fixed in firefox 49.0-1 (sid)2016
CVE-2016-5284 [HIGH] CVE-2016-5284: firefox - Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45....
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.
Scope: local
sid:
debian
CVE-2016-9068P3HIGHCVSS 7.5fixed in firefox 50.0-1 (sid)2016
CVE-2016-9068 [HIGH] CVE-2016-9068: firefox - A use-after-free during web animations when working with timelines resulting in ...
A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2025-1933P3HIGHCVSS 7.6fixed in firefox 136.0-1 (sid)2025
CVE-2025-1933 [HIGH] CVE-2025-1933: firefox - On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bi...
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
Scope: local
sid: resolved (fixed in 136.0-1)
debian
CVE-2024-0741P3MEDIUMCVSS 6.5fixed in firefox 122.0-1 (sid)2024
CVE-2024-0741 [MEDIUM] CVE-2024-0741: firefox - An out of bounds write in ANGLE could have allowed an attacker to corrupt memory...
An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Scope: local
sid: resolved (fixed in 122.0-1)
debian
CVE-2016-2831P4HIGHCVSS 8.8fixed in firefox 47.0-1 (sid)2016
CVE-2016-2831 [HIGH] CVE-2016-2831: firefox - Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that ...
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.
Scope: local
sid: resolved (fixed in 47.0-1)
debian
CVE-2023-5388P4MEDIUMCVSS 6.5fixed in firefox 124.0-1 (sid)2023
CVE-2023-5388 [MEDIUM] CVE-2023-5388: firefox - NSS was susceptible to a timing side-channel attack when performing RSA decrypti...
NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Scope: local
sid: resolved (fixed in 124.0-1)
debian
CVE-2026-0885P3MEDIUMCVSS 6.5fixed in firefox 147.0-1 (sid)2026
CVE-2026-0885 [MEDIUM] CVE-2026-0885: firefox - Use-after-free in the JavaScript: GC component. This vulnerability affects Firef...
Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
Scope: local
sid: resolved (fixed in 147.0-1)
debian
CVE-2025-14331P4MEDIUMCVSS 6.5fixed in firefox 146.0-1 (sid)2025
CVE-2025-14331 [MEDIUM] CVE-2025-14331: firefox - Same-origin policy bypass in the Request Handling component. This vulnerability ...
Same-origin policy bypass in the Request Handling component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
Scope: local
sid: resolved (fixed in 146.0-1)
debian
CVE-2017-16541P3LOWCVSS 6.5fixed in firefox 62.0-1 (sid)2017
CVE-2017-16541 [MEDIUM] CVE-2017-16541: firefox - Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass th...
Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
Scope: local
sid: resolved (fixed in 62.0-1)
debian