Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 34 of 49
CVE-2019-5798P4MEDIUMCVSS 6.5fixed in chromium 73.0.3683.75-1 (bookworm)2019
CVE-2019-5798 [MEDIUM] CVE-2019-5798: chromium - Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 a...
Lack of correct bounds checking in Skia in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 73.0.3683.75-1)
bullseye: resolved (fixed in 73.0.3683.75-1)
forky: resolved (fixed in 73.0.3683.75-1)
sid: resolved (fixed in 73.0.3683.75-1)
trixie: reso
debian
CVE-2016-2825P4MEDIUMCVSS 6.5fixed in firefox 47.0-1 (sid)2016
CVE-2016-2825 [MEDIUM] CVE-2016-2825: firefox - Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Po...
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
Scope: local
sid: resolved (fixed in 47.0-1)
debian
CVE-2017-7777P4HIGHCVSS 8.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7777 [HIGH] CVE-2017-7777: firefox - Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphit...
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2025-3028P4MEDIUMCVSS 6.5fixed in firefox 137.0-1 (sid)2025
CVE-2025-3028 [MEDIUM] CVE-2025-3028: firefox - JavaScript code running while transforming a document with the XSLTProcessor cou...
JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.
Scope: local
sid: resolved (fixed in 137.0-1)
debian
CVE-2018-18506P4MEDIUMCVSS 5.9fixed in firefox 65.0-1 (sid)2018
CVE-2018-18506 [MEDIUM] CVE-2018-18506: firefox - When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Config...
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on se
debian
CVE-2024-7531P4MEDIUMCVSS 6.5fixed in firefox 129.0-1 (sid)2024
CVE-2024-7531 [MEDIUM] CVE-2024-7531: firefox - Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input...
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite t
debian
CVE-2025-10532P4MEDIUMCVSS 6.5fixed in firefox 143.0-1 (sid)2025
CVE-2025-10532 [MEDIUM] CVE-2025-10532: firefox - Incorrect boundary conditions in the JavaScript: GC component. This vulnerabilit...
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2025-10529P4MEDIUMCVSS 6.5fixed in firefox 143.0-1 (sid)2025
CVE-2025-10529 [MEDIUM] CVE-2025-10529: firefox - Same-origin policy bypass in the Layout component. This vulnerability affects Fi...
Same-origin policy bypass in the Layout component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2006-5463P4HIGHCVSS 7.5fixed in firefox 45.0-1 (sid)2006
CVE-2006-5463 [HIGH] CVE-2006-5463: firefox - Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before ...
Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2017-7814P4HIGHCVSS 7.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7814 [HIGH] CVE-2017-7814: firefox - File downloads encoded with "blob:" and "data:" URL elements bypassed normal fil...
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firef
debian
CVE-2018-12365P4MEDIUMCVSS 6.5fixed in firefox 61.0-1 (sid)2018
CVE-2018-12365 [MEDIUM] CVE-2018-12365: firefox - A compromised IPC child process can escape the content sandbox and list the name...
A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
Scope: local
sid: resolved (fixe
debian
CVE-2016-1963P4HIGHCVSS 7.4fixed in firefox 45.0-1 (sid)2016
CVE-2016-1963 [HIGH] CVE-2016-1963: firefox - The FileReader class in Mozilla Firefox before 45.0 allows local users to gain p...
The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2816P4MEDIUMCVSS 6.5fixed in firefox 46.0-1 (sid)2016
CVE-2016-2816 [MEDIUM] CVE-2016-2816: firefox - Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Securi...
Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.
Scope: local
sid: resolved (fixed in 46.0-1)
debian
CVE-2023-6209P4MEDIUMCVSS 6.5fixed in firefox 120.0-1 (sid)2023
CVE-2023-6209 [MEDIUM] CVE-2023-6209: firefox - Relative URLs starting with three slashes were incorrectly parsed, and a path-tr...
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Scope: local
sid: resolved (fixed in 120.0-1)
debian
CVE-2020-26965P4MEDIUMCVSS 6.5fixed in firefox 83.0-1 (sid)2020
CVE-2020-26965 [MEDIUM] CVE-2020-26965: firefox - Some websites have a feature "Show Password" where clicking a button will change...
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility
debian
CVE-2023-6865P4MEDIUMCVSS 6.5fixed in firefox 121.0-1 (sid)2023
CVE-2023-6865 [MEDIUM] CVE-2023-6865: firefox - `EncryptingOutputStream` was susceptible to exposing uninitialized data. This i...
`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
debian
CVE-2023-37207P4MEDIUMCVSS 6.5fixed in firefox 115.0-1 (sid)2023
CVE-2023-37207 [MEDIUM] CVE-2023-37207: firefox - A website could have obscured the fullscreen notification by using a URL with a ...
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Scope: local
sid: resolved (fixed in 115.0-1)
debian
CVE-2017-7771P4HIGHCVSS 8.1fixed in firefox 54.0-1 (sid)2017
CVE-2017-7771 [HIGH] CVE-2017-7771: firefox - Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass:...
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2018-12396P4MEDIUMCVSS 6.5fixed in firefox 63.0-1 (sid)2018
CVE-2018-12396 [MEDIUM] CVE-2018-12396: firefox - A vulnerability where a WebExtension can run content scripts in disallowed conte...
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
Scope: local
sid: resolved (fixed in 63.0-1)
debian
CVE-2025-10527P4HIGHCVSS 7.1fixed in firefox 143.0-1 (sid)2025
CVE-2025-10527 [HIGH] CVE-2025-10527: firefox - Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This v...
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian