cbcvebase.

Debian Firefox-Esr vulnerabilities

965 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19

Vulnerabilities

Page 45 of 49
CVE-2023-6857P4MEDIUMCVSS 5.3fixed in firefox 121.0-1 (sid)2023
CVE-2023-6857 [MEDIUM] CVE-2023-6857: firefox - When resolving a symlink, a race may occur where the buffer passed to `readlink`... When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121. Scope: local sid: resolved (fixed in 121.0-1)
debian
CVE-2025-5267P4MEDIUMCVSS 5.4fixed in firefox 139.0-1 (sid)2025
CVE-2025-5267 [MEDIUM] CVE-2025-5267: firefox - A clickjacking vulnerability could have been used to trick a user into leaking s... A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. Scope: local sid: resolved (fixed in 139.0-1)
debian
CVE-2025-0243P4MEDIUMCVSS 5.1fixed in firefox 134.0-1 (sid)2025
CVE-2025-0243 [MEDIUM] CVE-2025-0243: firefox - Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, a... Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6. S
debian
CVE-2016-9077P4HIGHCVSS 7.0fixed in firefox 50.0-1 (sid)2016
CVE-2016-9077 [HIGH] CVE-2016-9077: firefox - Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-o... Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50. Scope: local sid: resolved (fixed in 50.0-1)
debian
CVE-2006-5748P4HIGHCVSS 5.0fixed in firefox 45.0-1 (sid)2006
CVE-2006-5748 [MEDIUM] CVE-2006-5748: firefox - Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox... Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger memory corruption. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2833P4MEDIUMCVSS 6.1fixed in firefox 47.0-1 (sid)2016
CVE-2016-2833 [MEDIUM] CVE-2016-2833: firefox - Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for... Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet. Scope: local sid: resolved (fixed in 47.0-1)
debian
CVE-2017-7823P4MEDIUMCVSS 5.4fixed in firefox 56.0-1 (sid)2017
CVE-2017-7823 [MEDIUM] CVE-2017-7823: firefox - The content security policy (CSP) "sandbox" directive did not create a unique or... The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4. Scope: lo
debian
CVE-2018-12383P4MEDIUMCVSS 5.5fixed in firefox 62.0-1 (sid)2018
CVE-2018-12383 [MEDIUM] CVE-2018-12383: firefox - If a user saved passwords before Firefox 58 and then later set a master password... If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored p
debian
CVE-2022-36318P4MEDIUMCVSS 5.3fixed in firefox 103.0-1 (sid)2022
CVE-2022-36318 [MEDIUM] CVE-2022-36318: firefox - When visiting directory listings for `chrome://` URLs as source text, some param... When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12. Scope: local sid: resolved (fixed in 103.0-1)
debian
CVE-2021-38509P4MEDIUMCVSS 4.3fixed in firefox 94.0-1 (sid)2021
CVE-2021-38509 [MEDIUM] CVE-2021-38509: firefox - Due to an unusual sequence of attacker-controlled events, a Javascript alert() d... Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3. Scope: local sid: resolved (fixed in 94.0-1)
debian
CVE-2025-4087P4MEDIUMCVSS 4.8fixed in firefox 138.0-1 (sid)2025
CVE-2025-4087 [MEDIUM] CVE-2025-4087: firefox - A vulnerability was identified in Thunderbird where XPath parsing could trigger ... A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null checks during attribute access. This could lead to out-of-bounds read access and potentially, memory corruption. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird < 128.10. Scope: local sid: resolved
debian
CVE-2016-2827P4MEDIUMCVSS 6.5fixed in firefox 49.0-1 (sid)2016
CVE-2016-2827 [MEDIUM] CVE-2016-2827: firefox - The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 ... The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2016-5271P4MEDIUMCVSS 6.5fixed in firefox 49.0-1 (sid)2016
CVE-2016-5271 [MEDIUM] CVE-2016-5271: firefox - The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0... The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2019-11715P4MEDIUMCVSS 6.1fixed in firefox 68.0-1 (sid)2019
CVE-2019-11715 [MEDIUM] CVE-2019-11715: firefox - Due to an error while parsing page content, it is possible for properly sanitize... Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: local sid: resolved (fixed in 68.0-1)
debian
CVE-2016-5262P4MEDIUMCVSS 6.1fixed in firefox 48.0-1 (sid)2016
CVE-2016-5262 [MEDIUM] CVE-2016-5262: firefox - Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript ... Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site. Scope: local sid: resolved (fixed in 48
debian
CVE-2019-11763P4MEDIUMCVSS 6.1fixed in firefox 70.0-1 (sid)2019
CVE-2019-11763 [MEDIUM] CVE-2019-11763: firefox - Failure to correctly handle null bytes when processing HTML entities resulted in... Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mas
debian
CVE-2017-5393P4MEDIUMCVSS 6.1fixed in firefox 51.0-1 (sid)2017
CVE-2017-5393 [MEDIUM] CVE-2017-5393: firefox - The "mozAddonManager" allows for the installation of extensions from the CDN for... The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51. Scope: local sid: resolved (fixed in 51.0-1)
debian
CVE-2016-5265P4MEDIUMCVSS 5.5fixed in firefox 48.0-1 (sid)2016
CVE-2016-5265 [MEDIUM] CVE-2016-5265: firefox - Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted... Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML document and a crafted shortcut file in the same local directory. Scope: local sid: resolved (fixed in 48.0-1)
debian
CVE-2020-12405P4MEDIUMCVSS 5.3fixed in firefox 77.0-1 (sid)2020
CVE-2020-12405 [MEDIUM] CVE-2020-12405: firefox - When browsing a malicious page, a race condition in our SharedWorkerService coul... When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. Scope: local sid: resolved (fixed in 77.0-1)
debian
CVE-2019-9797P4MEDIUMCVSS 5.3fixed in firefox 66.0-1 (sid)2019
CVE-2019-9797 [MEDIUM] CVE-2019-9797: firefox - Cross-origin images can be read in violation of the same-origin policy by export... Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66. Scope: local sid: resolved (fixed in 66.0-1)
debian
Debian Firefox-Esr vulnerabilities | cvebase