cbcvebase.

Debian Firefox-Esr vulnerabilities

965 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19

Vulnerabilities

Page 44 of 49
CVE-2019-11717P4MEDIUMCVSS 5.3fixed in firefox 68.0-1 (sid)2019
CVE-2019-11717 [MEDIUM] CVE-2019-11717: firefox - A vulnerability exists where the caret ("^") character is improperly escaped con... A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: local sid: resolved (fixed in 68.0-1)
debian
CVE-2006-6498P4HIGHCVSS 6.8fixed in firefox 45.0-1 (sid)2006
CVE-2006-6498 [MEDIUM] CVE-2006-6498: firefox - Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefo... Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, SeaMonkey before 1.0.7, and Mozilla 1.7 and probably earlier on Solaris, allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown impact and at
debian
CVE-2006-6497P4MEDIUMCVSS 6.8fixed in firefox 45.0-1 (sid)2006
CVE-2006-6497 [MEDIUM] CVE-2006-6497: firefox - Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.... Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2017-7764P4MEDIUMCVSS 5.3fixed in firefox 54.0-1 (sid)2017
CVE-2017-7764 [MEDIUM] CVE-2017-7764: firefox - Characters from the "Canadian Syllabics" unicode block can be mixed with charact... Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syllabics to be m
debian
CVE-2019-13075P4LOWCVSS 5.3fixed in firefox 68.0-1 (sid)2019
CVE-2019-13075 [MEDIUM] CVE-2019-13075: firefox - Tor Browser through 8.5.3 has an information exposure vulnerability. It allows r... Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68. Scope: local sid: resolved (fixed in 68.
debian
CVE-2023-6206P4MEDIUMCVSS 5.4fixed in firefox 120.0-1 (sid)2023
CVE-2023-6206 [MEDIUM] CVE-2023-6206: firefox - The black fade animation when exiting fullscreen is roughly the length of the an... The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. Scope: local sid:
debian
CVE-2024-11695P4MEDIUMCVSS 5.4fixed in firefox 133.0-1 (sid)2024
CVE-2024-11695 [MEDIUM] CVE-2024-11695: firefox - A crafted URL containing Arabic script and whitespace characters could have hidd... A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5. Scope: local sid: resolved (fixed in 133.0-1)
debian
CVE-2026-0890P4MEDIUMCVSS 5.4fixed in firefox 147.0-1 (sid)2026
CVE-2026-0890 [MEDIUM] CVE-2026-0890: firefox - Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerab... Spoofing issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7. Scope: local sid: resolved (fixed in 147.0-1)
debian
CVE-2006-5462P4HIGHCVSS 4.0fixed in firefox 45.0-1 (sid)2006
CVE-2006-5462 [MEDIUM] CVE-2006-5462: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla... Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for u
debian
CVE-2016-9895P4MEDIUMCVSS 6.1fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9895 [MEDIUM] CVE-2016-9895: firefox - Event handlers on "marquee" elements were executed despite a strict Content Secu... Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. Scope: local sid: resolved (fixed in 50.1.0-1)
debian
CVE-2019-11744P4MEDIUMCVSS 6.1fixed in firefox 69.0-1 (sid)2019
CVE-2019-11744 [MEDIUM] CVE-2019-11744: firefox - Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain lite... Some HTML elements, such as and , can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as it does for ot
debian
CVE-2021-43543P4MEDIUMCVSS 6.1fixed in firefox 95.0-1 (sid)2021
CVE-2021-43543 [MEDIUM] CVE-2021-43543: firefox - Documents loaded with the CSP sandbox directive could have escaped the sandbox's... Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. Scope: local sid: resolved (fixed in 95.0-1)
debian
CVE-2020-26956P4MEDIUMCVSS 6.1fixed in firefox 83.0-1 (sid)2020
CVE-2020-26956 [MEDIUM] CVE-2020-26956: firefox - In some cases, removing HTML elements during sanitization would keep existing SV... In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5. Scope: local sid: resolved (fixed in 83.0-1)
debian
CVE-2017-5383P4MEDIUMCVSS 5.3fixed in firefox 51.0-1 (sid)2017
CVE-2017-5383 [MEDIUM] CVE-2017-5383: firefox - URLs containing certain unicode glyphs for alternative hyphens and quotes do not... URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. Scope: local sid: resolved (fixed in 51.0-1)
debian
CVE-2016-2817P4MEDIUMCVSS 5.4fixed in firefox 46.0-1 (sid)2016
CVE-2016-2817 [MEDIUM] CVE-2016-2817: firefox - The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in... The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL. Scope:
debian
CVE-2023-4046P4MEDIUMCVSS 5.3fixed in firefox 116.0-1 (sid)2023
CVE-2023-4046 [MEDIUM] CVE-2023-4046: firefox - In some circumstances, a stale value could have been used for a global variable ... In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Scope: local sid: resolved (fixed in 116.0-1)
debian
CVE-2016-5291P4MEDIUMCVSS 5.5fixed in firefox 50.0-1 (sid)2016
CVE-2016-5291 [MEDIUM] CVE-2016-5291: firefox - A same-origin policy bypass with local shortcut files to load arbitrary local co... A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50. Scope: local sid: resolved (fixed in 50.0-1)
debian
CVE-2020-12392P4MEDIUMCVSS 5.5fixed in firefox 76.0-1 (sid)2020
CVE-2020-12392 [MEDIUM] CVE-2020-12392: firefox - The 'Copy as cURL' feature of Devtools' network tab did not properly escape the ... The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird <
debian
CVE-2022-28286P4MEDIUMCVSS 5.4fixed in firefox 99.0-1 (sid)2022
CVE-2022-28286 [MEDIUM] CVE-2022-28286: firefox - Due to a layout change, iframe contents could have been rendered outside of its ... Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8. Scope: local sid: resolved (fixed in 99.0-1)
debian
CVE-2023-25730P4MEDIUMCVSS 5.4fixed in firefox 110.0-1 (sid)2023
CVE-2023-25730 [MEDIUM] CVE-2023-25730: firefox - A background script invoking <code>requestFullscreen</code> and then blocking th... A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. Scope: local sid: resolved (fixed in 110.0-1)
debian
Debian Firefox-Esr vulnerabilities | cvebase