cbcvebase.

Debian Firefox-Esr vulnerabilities

965 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19

Vulnerabilities

Page 37 of 49
CVE-2023-29548P4MEDIUMCVSS 6.5fixed in firefox 112.0-1 (sid)2023
CVE-2023-29548 [MEDIUM] CVE-2023-29548: firefox - A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optim... A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10. Scope: local sid: resolved (fixed in 112.0-1)
debian
CVE-2022-22739P4MEDIUMCVSS 6.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22739 [MEDIUM] CVE-2022-22739: firefox - Malicious websites could have tricked users into accepting launching a program t... Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2023-25728P4MEDIUMCVSS 6.5fixed in firefox 110.0-1 (sid)2023
CVE-2023-25728 [MEDIUM] CVE-2023-25728: firefox - The <code>Content-Security-Policy-Report-Only</code> header could allow an attac... The Content-Security-Policy-Report-Only header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. Scope: local sid: resolved (fixed in 110.0-1)
debian
CVE-2022-22754P4MEDIUMCVSS 6.5fixed in firefox 97.0-1 (sid)2022
CVE-2022-22754 [MEDIUM] CVE-2022-22754: firefox - If a user installed an extension of a particular type, the extension could have ... If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6. Scope: local sid: resolved (fixed in 97.0-1)
debian
CVE-2023-4577P4MEDIUMCVSS 6.5fixed in firefox 117.0-1 (sid)2023
CVE-2023-4577 [MEDIUM] CVE-2023-4577: firefox - When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could alre... When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2. Scope: local sid: resolved (fixed in 117.0-1)
debian
CVE-2023-23603P4MEDIUMCVSS 6.5fixed in firefox 109.0-1 (sid)2023
CVE-2023-23603 [MEDIUM] CVE-2023-23603: firefox - Regular expressions used to filter out forbidden properties and values from styl... Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. Scope: local sid: resolved (fixed in 109.0-1)
debian
CVE-2023-4573P4MEDIUMCVSS 6.5fixed in firefox 117.0-1 (sid)2023
CVE-2023-4573 [MEDIUM] CVE-2023-4573: firefox - When receiving rendering data over IPC `mStream` could have been destroyed when ... When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2. Scope: local sid: resolved (fixed in 117.0-1)
debian
CVE-2022-45404P4MEDIUMCVSS 6.5fixed in firefox 107.0-1 (sid)2022
CVE-2022-45404 [MEDIUM] CVE-2022-45404: firefox - Through a series of popup and <code>window.print()</code> calls, an attacker can... Through a series of popup and window.print() calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107. Scope: local sid: resolved (fixed in 107.0-1)
debian
CVE-2023-23602P4MEDIUMCVSS 6.5fixed in firefox 109.0-1 (sid)2023
CVE-2023-23602 [MEDIUM] CVE-2023-23602: firefox - A mishandled security check when creating a WebSocket in a WebWorker caused the ... A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7. Scope: local sid: resolved (fixed in 109.0-1)
debian
CVE-2024-0747P4MEDIUMCVSS 6.5fixed in firefox 122.0-1 (sid)2024
CVE-2024-0747 [MEDIUM] CVE-2024-0747: firefox - When a parent page loaded a child in an iframe with `unsafe-inline`, the parent ... When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7. Scope: local sid: resolved (fixed in 122.0-1)
debian
CVE-2024-10464P4MEDIUMCVSS 6.5fixed in firefox 132.0-1 (sid)2024
CVE-2024-10464 [MEDIUM] CVE-2024-10464: firefox - Repeated writes to history interface attributes could have been used to cause a ... Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132. Scope: local sid: resolved (fixed in 132.0-1)
debian
CVE-2024-7526P4MEDIUMCVSS 6.5fixed in firefox 129.0-1 (sid)2024
CVE-2024-7526 [MEDIUM] CVE-2024-7526: firefox - ANGLE failed to initialize parameters which lead to reading from uninitialized m... ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14. Scope: local sid: resolved (fixed in 129.0-1)
debian
CVE-2022-38472P4MEDIUMCVSS 6.5fixed in firefox 104.0-1 (sid)2022
CVE-2022-38472 [MEDIUM] CVE-2022-38472: firefox - An attacker could have abused XSLT error handling to associate attacker-controll... An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Fir
debian
CVE-2025-9181P4MEDIUMCVSS 6.5fixed in firefox 142.0-1 (sid)2025
CVE-2025-9181 [MEDIUM] CVE-2025-9181: firefox - Uninitialized memory in the JavaScript Engine component. This vulnerability affe... Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. Scope: local sid: resolved (fixed in 142.0-1)
debian
CVE-2025-8033P4MEDIUMCVSS 6.5fixed in firefox 141.0-1 (sid)2025
CVE-2025-8033 [MEDIUM] CVE-2025-8033: firefox - The JavaScript engine did not handle closed generators correctly and it was poss... The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. Scope: local sid: resolved (fixed in 141.0-1)
debian
CVE-2016-5288P4MEDIUMCVSS 5.9fixed in firefox 50.0-1 (sid)2016
CVE-2016-5288 [MEDIUM] CVE-2016-5288: firefox - Web content could access information in the HTTP cache if e10s is disabled. This... Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2. Scope: local sid: resolved (fixed in 50.0-1)
debian
CVE-2019-9793P4MEDIUMCVSS 5.9fixed in firefox 66.0-1 (sid)2019
CVE-2019-9793 [MEDIUM] CVE-2019-9793: firefox - A mechanism was discovered that removes some bounds checking for string, array, ... A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have explicitly disa
debian
CVE-2017-5384P4MEDIUMCVSS 5.9fixed in firefox 51.0-1 (sid)2017
CVE-2017-5384 [MEDIUM] CVE-2017-5384: firefox - Proxy Auto-Config (PAC) files can specify a JavaScript function called for all U... Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information than would be sent to the proxy itself in the case of HTTPS. Normally the Proxy Auto-Config file is specified by the user or machine owner and presumed to be non-malicious, but if a user has enabled Web Proxy Auto Detect (
debian
CVE-2016-1967P4MEDIUMCVSS 5.0fixed in firefox 45.0-1 (sid)2016
CVE-2016-1967 [MEDIUM] CVE-2016-1967: firefox - Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAM... Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because
debian
CVE-2018-12366P4MEDIUMCVSS 6.5fixed in firefox 61.0-1 (sid)2018
CVE-2018-12366 [MEDIUM] CVE-2018-12366: firefox - An invalid grid size during QCMS (color profile) transformations can result in t... An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61. Scope: local sid: resolved (fixed in 61.0-1)
debian
Debian Firefox-Esr vulnerabilities | cvebase