cbcvebase.

Debian Firefox-Esr vulnerabilities

965 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19

Vulnerabilities

Page 39 of 49
CVE-2022-22745P4MEDIUMCVSS 6.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22745 [MEDIUM] CVE-2022-22745: firefox - Securitypolicyviolation events could have leaked cross-origin information for fr... Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2023-1945P4MEDIUMCVSS 6.5fixed in firefox-esr 102.10.0esr-1 (bookworm)2023
CVE-2023-1945 [MEDIUM] CVE-2023-1945: firefox-esr - Unexpected data returned from the Safe Browsing API could have led to memory cor... Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 102.10 and Firefox ESR < 102.10. Scope: local bookworm: resolved (fixed in 102.10.0esr-1) bullseye: resolved (fixed in 102.10.0esr-1~deb11u1) forky: resolved (fixed in 102.10.0esr-1) sid: resolved (
debian
CVE-2022-29914P4MEDIUMCVSS 6.5fixed in firefox 100.0-1 (sid)2022
CVE-2022-29914 [MEDIUM] CVE-2022-29914: firefox - When reusing existing popups Firefox would have allowed them to cover the fullsc... When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. Scope: local sid: resolved (fixed in 100.0-1)
debian
CVE-2022-31742P4MEDIUMCVSS 6.5fixed in firefox 101.0-1 (sid)2022
CVE-2022-31742 [MEDIUM] CVE-2022-31742: firefox - An attacker could have exploited a timing attack by sending a large number of al... An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope
debian
CVE-2022-31738P4MEDIUMCVSS 6.5fixed in firefox 101.0-1 (sid)2022
CVE-2022-31738 [MEDIUM] CVE-2022-31738: firefox - When exiting fullscreen mode, an iframe could have confused the browser about th... When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope: local sid: resolved (fixed in 101.0-1)
debian
CVE-2023-4580P4MEDIUMCVSS 6.5fixed in firefox 117.0-1 (sid)2023
CVE-2023-4580 [MEDIUM] CVE-2023-4580: firefox - Push notifications stored on disk in private browsing mode were not being encryp... Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2. Scope: local sid: resolved (fixed in 117.0-1)
debian
CVE-2025-8027P4MEDIUMCVSS 6.5fixed in firefox 141.0-1 (sid)2025
CVE-2025-8027 [MEDIUM] CVE-2025-8027: firefox - On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value ... On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. Scope: local sid: resolved (fixed in 141.0-1)
debian
CVE-2023-28164P4MEDIUMCVSS 6.5fixed in firefox 111.0-1 (sid)2023
CVE-2023-28164 [MEDIUM] CVE-2023-28164: firefox - Dragging a URL from a cross-origin iframe that was removed during the drag could... Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9. Scope: local sid: resolved (fixed in 111.0-1)
debian
CVE-2024-2610P4MEDIUMCVSS 6.1fixed in firefox 124.0-1 (sid)2024
CVE-2024-2610 [MEDIUM] CVE-2024-2610: firefox - Using a markup injection an attacker could have stolen nonce values. This could ... Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. Scope: local sid: resolved (fixed in 124.0-1)
debian
CVE-2024-3859P4MEDIUMCVSS 5.9fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3859 [MEDIUM] CVE-2024-3859: firefox - On 32-bit versions there were integer-overflows that led to an out-of-bounds-rea... On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
CVE-2025-0237P4MEDIUMCVSS 5.4fixed in firefox 134.0-1 (sid)2025
CVE-2025-0237 [MEDIUM] CVE-2025-0237: firefox - The WebChannel API, which is used to transport various information across proces... The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6. Scope: local sid: resolved (fixed in 134.
debian
CVE-2006-6501P4HIGHCVSS 6.8fixed in firefox 45.0-1 (sid)2006
CVE-2006-6501 [MEDIUM] CVE-2006-6501: firefox - Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.... Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2018-18494P4MEDIUMCVSS 6.5fixed in firefox 64.0-1 (sid)2018
CVE-2018-18494 [MEDIUM] CVE-2018-18494: firefox - A same-origin policy violation allowing the theft of cross-origin URL entries wh... A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64. Scope: local sid:
debian
CVE-2020-15652P4MEDIUMCVSS 6.5fixed in firefox 79.0-1 (sid)2020
CVE-2020-15652 [MEDIUM] CVE-2020-15652: firefox - By observing the stack trace for JavaScript errors in web workers, it was possib... By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1. Scope: local sid: resolved (fixed in 79.0-1)
debian
CVE-2021-29945P4MEDIUMCVSS 6.5fixed in firefox 88.0-1 (sid)2021
CVE-2021-29945 [MEDIUM] CVE-2021-29945: firefox - The WebAssembly JIT could miscalculate the size of a return type, which could le... The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88. Scope: local sid: resolved (fixed in 88.0-1)
debian
CVE-2019-5785P4MEDIUMCVSS 6.5fixed in firefox 65.0.1-1 (sid)2019
CVE-2019-5785 [MEDIUM] CVE-2019-5785: firefox - Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 ... Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. Scope: local sid: resolved (fixed in 65.0.1-1)
debian
CVE-2020-26961P4MEDIUMCVSS 6.5fixed in firefox 83.0-1 (sid)2020
CVE-2020-26961 [MEDIUM] CVE-2020-26961: firefox - When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP r... When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR < 78.5,
debian
CVE-2018-18499P4MEDIUMCVSS 6.5fixed in firefox 62.0-1 (sid)2018
CVE-2018-18499 [MEDIUM] CVE-2018-18499: firefox - A same-origin policy violation allowing the theft of cross-origin URL entries wh... A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1. Scope: loc
debian
CVE-2019-11748P4MEDIUMCVSS 6.5fixed in firefox 69.0-1 (sid)2019
CVE-2019-11748 [MEDIUM] CVE-2019-11748: firefox - WebRTC in Firefox will honor persisted permissions given to sites for access to ... WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This avoids the possibility of trusted WebRTC resources being invisibly embedded in web con
debian
CVE-2016-9074P4MEDIUMCVSS 5.9fixed in firefox-esr 45.5.0esr-1 (bookworm)2016
CVE-2016-9074 [MEDIUM] CVE-2016-9074: firefox-esr - An existing mitigation of timing side-channel attacks is insufficient in some ci... An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50. Scope: local bookworm: resolved (fixed in 45.5.0esr-1) bullseye: resolved (fixed in 45.5.0esr-1) forky: resolved (fixed
debian
Debian Firefox-Esr vulnerabilities | cvebase