Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 40 of 49
CVE-2020-16042P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16042 [MEDIUM] CVE-2020-16042: chromium - Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote ...
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88
debian
CVE-2023-6205P4MEDIUMCVSS 6.5fixed in firefox 120.0-1 (sid)2023
CVE-2023-6205 [MEDIUM] CVE-2023-6205: firefox - It was possible to cause the use of a MessagePort after it had already been free...
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Scope: local
sid: resolved (fixed in 120.0-1)
debian
CVE-2022-22742P4MEDIUMCVSS 6.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22742 [MEDIUM] CVE-2022-22742: firefox - When inserting text while in edit mode, some characters might have lead to out-o...
When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved (fixed in 96.0-1)
debian
CVE-2023-29535P4MEDIUMCVSS 6.5fixed in firefox 112.0-1 (sid)2023
CVE-2023-29535 [MEDIUM] CVE-2023-29535: firefox - Following a Garbage Collector compaction, weak maps may have been accessed befor...
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
Scope: local
sid: resolved (fixed in 112.0
debian
CVE-2024-0746P4MEDIUMCVSS 6.5fixed in firefox 122.0-1 (sid)2024
CVE-2024-0746 [MEDIUM] CVE-2024-0746: firefox - A Linux user opening the print preview dialog could have caused the browser to c...
A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Scope: local
sid: resolved (fixed in 122.0-1)
debian
CVE-2022-45403P4MEDIUMCVSS 6.5fixed in firefox 107.0-1 (sid)2022
CVE-2022-45403 [MEDIUM] CVE-2022-45403: firefox - Service Workers should not be able to infer information about opaque cross-origi...
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Scope: local
sid: resolved (fixed
debian
CVE-2021-23998P4MEDIUMCVSS 6.5fixed in firefox 88.0-1 (sid)2021
CVE-2021-23998 [MEDIUM] CVE-2021-23998: firefox - Through complicated navigations with new windows, an HTTP page could have inheri...
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2021-38497P4MEDIUMCVSS 6.5fixed in firefox 93.0-1 (sid)2021
CVE-2021-38497 [MEDIUM] CVE-2021-38497: firefox - Through use of reportValidity() and window.open(), a plain-text validation messa...
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
Scope: local
sid: resolved (fixed in 93.0-1)
debian
CVE-2023-23601P4MEDIUMCVSS 6.5fixed in firefox 109.0-1 (sid)2023
CVE-2023-23601 [MEDIUM] CVE-2023-23601: firefox - Navigations were being allowed when dragging a URL from a cross-origin iframe in...
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
Scope: local
sid: resolved (fixed in 109.0-1)
debian
CVE-2016-9076P4MEDIUMCVSS 5.9fixed in firefox 50.0-1 (sid)2016
CVE-2016-9076 [MEDIUM] CVE-2016-9076: firefox - An issue where a "<select>" dropdown menu can be used to cover location bar cont...
An issue where a "" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. This vulnerability affects Firefox < 50.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2025-11711P4MEDIUMCVSS 6.5fixed in firefox 144.0-1 (sid)2025
CVE-2025-11711 [MEDIUM] CVE-2025-11711: firefox - There was a way to change the value of JavaScript Object properties that were su...
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
Scope: local
sid: resolved (fixed in 144.0-1)
debian
CVE-2024-2609P4MEDIUMCVSS 6.1fixed in firefox 124.0-1 (sid)2024
CVE-2024-2609 [MEDIUM] CVE-2024-2609: firefox - The permission prompt input delay could expire while the window is not in focus....
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
Scope: local
sid: resolved (fixed in 124.0-1)
debian
CVE-2024-5693P4MEDIUMCVSS 6.1fixed in firefox 127.0-1 (sid)2024
CVE-2024-5693 [MEDIUM] CVE-2024-5693: firefox - Offscreen Canvas did not properly track cross-origin tainting, which could be us...
Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2023-4049P4MEDIUMCVSS 5.9fixed in firefox 116.0-1 (sid)2023
CVE-2023-4049 [MEDIUM] CVE-2023-4049: firefox - Race conditions in reference counting code were found through code inspection. T...
Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Scope: local
sid: resolved (fixed in 116.0-1)
debian
CVE-2017-7791P4MEDIUMCVSS 5.3fixed in firefox 55.0-1 (sid)2017
CVE-2017-7791 [MEDIUM] CVE-2017-7791: firefox - On pages containing an iframe, the "data:" protocol can be used to create a moda...
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2021-29955P4MEDIUMCVSS 5.3fixed in firefox 87.0-1 (sid)2021
CVE-2021-29955 [MEDIUM] CVE-2021-29955: firefox - A transient execution vulnerability, named Floating Point Value Injection (FPVI)...
A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.
Scope: local
sid: reso
debian
CVE-2019-11698P4MEDIUMCVSS 5.3fixed in firefox 67.0-2 (sid)2019
CVE-2019-11698 [MEDIUM] CVE-2019-11698: firefox - If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and...
If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This vulnerability
debian
CVE-2016-1956P4MEDIUMCVSS 6.5fixed in firefox 45.0-1 (sid)2016
CVE-2016-1956 [MEDIUM] CVE-2016-1956: firefox - Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows...
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2021-43545P4MEDIUMCVSS 6.5fixed in firefox 95.0-1 (sid)2021
CVE-2021-43545 [MEDIUM] CVE-2021-43545: firefox - Using the Location API in a loop could have caused severe application hangs and ...
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Scope: local
sid: resolved (fixed in 95.0-1)
debian
CVE-2016-5260P4MEDIUMCVSS 6.5fixed in firefox 48.0-1 (sid)2016
CVE-2016-5260 [MEDIUM] CVE-2016-5260: firefox - Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to '...
Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file.
Scope: local
sid: resolved (fixed in 48.0-1)
debian