Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 43 of 49
CVE-2020-6812P4MEDIUMCVSS 5.3fixed in firefox 74.0-1 (sid)2020
CVE-2020-6812 [MEDIUM] CVE-2020-6812: firefox - The first time AirPods are connected to an iPhone, they become named after the u...
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'.
debian
CVE-2024-2611P4MEDIUMCVSS 5.5fixed in firefox 124.0-1 (sid)2024
CVE-2024-2611 [MEDIUM] CVE-2024-2611: firefox - A missing delay on when pointer lock was used could have allowed a malicious pag...
A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Scope: local
sid: resolved (fixed in 124.0-1)
debian
CVE-2019-11761P4MEDIUMCVSS 5.4fixed in firefox 70.0-1 (sid)2019
CVE-2019-11761 [MEDIUM] CVE-2019-11761: firefox - By using a form with a data URI it was possible to gain access to the privileged...
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
Scope: local
sid: resolved (
debian
CVE-2024-11696P4MEDIUMCVSS 5.4fixed in firefox 133.0-1 (sid)2024
CVE-2024-11696 [MEDIUM] CVE-2024-11696: firefox - The application failed to account for exceptions thrown by the `loadManifestFrom...
The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated add-ons may have
debian
CVE-2023-4045P4MEDIUMCVSS 5.3fixed in firefox 116.0-1 (sid)2023
CVE-2023-4045 [MEDIUM] CVE-2023-4045: firefox - Offscreen Canvas did not properly track cross-origin tainting, which could have ...
Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Scope: local
sid: resolved (fixed in 116.0-1)
debian
CVE-2016-5292P4MEDIUMCVSS 6.5fixed in firefox 50.0-1 (sid)2016
CVE-2016-5292 [MEDIUM] CVE-2016-5292: firefox - During URL parsing, a maliciously crafted URL can cause a potentially exploitabl...
During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2019-17022P4MEDIUMCVSS 6.1fixed in firefox 72.0-1 (sid)2019
CVE-2019-17022 [MEDIUM] CVE-2019-17022: firefox - When pasting a <style> tag from the clipboard into a rich text editor, the...
When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer does not escape characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, this would resu
debian
CVE-2016-9903P4MEDIUMCVSS 6.1fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9903 [MEDIUM] CVE-2016-9903: firefox - Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vul...
Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context. This vulnerability affects Firefox < 50.1.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2017-5389P4MEDIUMCVSS 6.1fixed in firefox 51.0-1 (sid)2017
CVE-2017-5389 [MEDIUM] CVE-2017-5389: firefox - WebExtensions could use the "mozAddonManager" API by modifying the CSP headers o...
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.
Scope: local
sid: resolve
debian
CVE-2022-40956P4MEDIUMCVSS 6.1fixed in firefox 105.0-1 (sid)2022
CVE-2022-40956 [MEDIUM] CVE-2022-40956: firefox - When injecting an HTML base element, some requests would ignore the CSP's base-u...
When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
Scope: local
sid: resolved (fixed in 105.0-1)
debian
CVE-2022-45418P4MEDIUMCVSS 6.1fixed in firefox 107.0-1 (sid)2022
CVE-2022-45418 [MEDIUM] CVE-2022-45418: firefox - If a custom mouse cursor is specified in CSS, under certain circumstances the cu...
If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Scope: local
sid: resolved (fixed in 107.0-1)
debian
CVE-2022-29912P4MEDIUMCVSS 6.1fixed in firefox 100.0-1 (sid)2022
CVE-2022-29912 [MEDIUM] CVE-2022-29912: firefox - Requests initiated through reader mode did not properly omit cookies with a Same...
Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
Scope: local
sid: resolved (fixed in 100.0-1)
debian
CVE-2017-5408P4MEDIUMCVSS 5.3fixed in firefox 52.0-1 (sid)2017
CVE-2017-5408 [MEDIUM] CVE-2017-5408: firefox - Video files loaded video captions cross-origin without checking for the presence...
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Scope: local
sid: resolved (fixed in 52.0-1)
debian
CVE-2017-5405P4MEDIUMCVSS 5.3fixed in firefox 52.0-1 (sid)2017
CVE-2017-5405 [MEDIUM] CVE-2017-5405: firefox - Certain response codes in FTP connections can result in the use of uninitialized...
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Scope: local
sid: resolved (fixed in 52.0-1)
debian
CVE-2019-11762P4MEDIUMCVSS 6.1fixed in firefox 70.0-1 (sid)2019
CVE-2019-11762 [MEDIUM] CVE-2019-11762: firefox - If two same-origin documents set document.domain differently to become cross-ori...
If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
Scope: local
sid: resolved (fixed in 70.0-1)
debian
CVE-2025-10536P4MEDIUMCVSS 6.2fixed in firefox 143.0-1 (sid)2025
CVE-2025-10536 [MEDIUM] CVE-2025-10536: firefox - Information disclosure in the Networking: Cache component. This vulnerability af...
Information disclosure in the Networking: Cache component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2018-5117P4MEDIUMCVSS 5.3fixed in firefox 58.0-1 (sid)2018
CVE-2018-5117 [MEDIUM] CVE-2018-5117: firefox - If right-to-left text is used in the addressbar with left-to-right alignment, it...
If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird < 52.6, F
debian
CVE-2018-5168P4MEDIUMCVSS 5.3fixed in firefox 60.0-1 (sid)2018
CVE-2018-5168 [MEDIUM] CVE-2018-5168: firefox - Sites can bypass security checks on permissions to install lightweight themes by...
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox
debian
CVE-2025-11712P4MEDIUMCVSS 6.1fixed in firefox 144.0-1 (sid)2025
CVE-2025-11712 [MEDIUM] CVE-2025-11712: firefox - A malicious page could have used the type attribute of an OBJECT tag to override...
A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encountering a web resource served without a content-type. This could have contributed to an XSS on a site that unsafely serves files without a content-type header. This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and
debian
CVE-2025-6430P4MEDIUMCVSS 6.1fixed in firefox 140.0-1 (sid)2025
CVE-2025-6430 [MEDIUM] CVE-2025-6430: firefox - When a file download is specified via the `Content-Disposition` header, that dir...
When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a ` ` or ` ` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12.
Scope: local
sid: resolved (fixed
debian