Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 46 of 49
CVE-2019-9817P4MEDIUMCVSS 5.3fixed in firefox 67.0-2 (sid)2019
CVE-2019-9817 [MEDIUM] CVE-2019-9817: firefox - Images from a different domain can be read using a canvas object in some circums...
Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Scope: local
sid: resolved (fixed in 67.0-2)
debian
CVE-2024-5691P4MEDIUMCVSS 4.7fixed in firefox 127.0-1 (sid)2024
CVE-2024-5691 [MEDIUM] CVE-2024-5691: firefox - By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe coul...
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2025-5264P4MEDIUMCVSS 4.8fixed in firefox 139.0-1 (sid)2025
CVE-2025-5264 [MEDIUM] CVE-2025-5264: firefox - Due to insufficient escaping of the newline character in the “Copy as cURL” feat...
Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's system. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
Scope: local
sid: resolved (fi
debian
CVE-2024-6601P4MEDIUMCVSS 4.7fixed in firefox 128.0-1 (sid)2024
CVE-2024-6601 [MEDIUM] CVE-2024-6601: firefox - A race condition could lead to a cross-origin container obtaining permissions of...
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
Scope: local
sid: resolved (fixed in 128.0-1)
debian
CVE-2006-6585P4MEDIUMCVSS 6.4fixed in firefox 45.0-1 (sid)2006
CVE-2006-6585 [MEDIUM] CVE-2006-6585: firefox - The Extensions manager in Mozilla Firefox 2.0 does not properly populate the lis...
The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated by the FFsniFF extension. NOTE: it was later reported that 3.0 is also affected.
Scope: local
sid: resolved (fixed in
debian
CVE-2006-6503P4HIGHCVSS 6.8fixed in firefox 45.0-1 (sid)2006
CVE-2006-6503 [MEDIUM] CVE-2006-6503: firefox - Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5...
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2006-6502P4HIGHCVSS 7.1fixed in firefox 45.0-1 (sid)2006
CVE-2006-6502 [HIGH] CVE-2006-6502: firefox - Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox ...
Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2007-0801P4LOWCVSS 4.3fixed in firefox 45.0-1 (sid)2007
CVE-2007-0801 [MEDIUM] CVE-2007-0801: firefox - The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 crea...
The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2832P4MEDIUMCVSS 4.3fixed in firefox 47.0-1 (sid)2016
CVE-2016-2832 [MEDIUM] CVE-2016-2832: firefox - Mozilla Firefox before 47.0 allows remote attackers to discover the list of disa...
Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
Scope: local
sid: resolved (fixed in 47.0-1)
debian
CVE-2016-2820P4MEDIUMCVSS 4.3fixed in firefox 46.0-1 (sid)2016
CVE-2016-2820 [MEDIUM] CVE-2016-2820: firefox - The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Fi...
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.
Scope: local
sid: resolved (fixed in 46.0-1)
debian
CVE-2024-1548P4MEDIUMCVSS 4.3fixed in firefox 123.0-1 (sid)2024
CVE-2024-1548 [MEDIUM] CVE-2024-1548: firefox - A website could have obscured the fullscreen notification by using a dropdown se...
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
Scope: local
sid: resolved (fixed in 123.0-1)
debian
CVE-2023-5725P4MEDIUMCVSS 4.3fixed in firefox 119.0-1 (sid)2023
CVE-2023-5725 [MEDIUM] CVE-2023-5725: firefox - A malicious installed WebExtension could open arbitrary URLs, which under the ri...
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
Scope: local
sid: resolved (fixed in 119.0-1)
debian
CVE-2024-5690P4MEDIUMCVSS 4.3fixed in firefox 127.0-1 (sid)2024
CVE-2024-5690 [MEDIUM] CVE-2024-5690: firefox - By monitoring the time certain operations take, an attacker could have guessed w...
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2024-11692P4MEDIUMCVSS 4.3fixed in firefox 133.0-1 (sid)2024
CVE-2024-11692 [MEDIUM] CVE-2024-11692: firefox - An attacker could cause a select dropdown to be shown over another tab; this cou...
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Scope: local
sid: resolved (fixed in 133.0-1)
debian
CVE-2020-16012P4MEDIUMCVSS 4.3fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16012 [MEDIUM] CVE-2020-16012: chromium - Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280...
Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: res
debian
CVE-2016-1965P4MEDIUMCVSS 4.3fixed in firefox 45.0-1 (sid)2016
CVE-2016-1965 [MEDIUM] CVE-2016-1965: firefox - Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigat...
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2021-38508P4MEDIUMCVSS 4.3fixed in firefox 94.0-1 (sid)2021
CVE-2021-38508 [MEDIUM] CVE-2021-38508: firefox - By displaying a form validity message in the correct location at the same time a...
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
sid: res
debian
CVE-2021-38506P4MEDIUMCVSS 4.3fixed in firefox 94.0-1 (sid)2021
CVE-2021-38506 [MEDIUM] CVE-2021-38506: firefox - Through a series of navigations, Firefox could have entered fullscreen mode with...
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
sid: resolved (fixed in 94.0-1)
debian
CVE-2020-26953P4MEDIUMCVSS 4.3fixed in firefox 83.0-1 (sid)2020
CVE-2020-26953 [MEDIUM] CVE-2020-26953: firefox - It was possible to cause the browser to enter fullscreen mode without displaying...
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Scope: local
sid: resolved (fixed in 83.0-1)
debian
CVE-2020-35111P4MEDIUMCVSS 4.3fixed in firefox 84.0-1 (sid)2020
CVE-2020-35111 [MEDIUM] CVE-2020-35111: firefox - When an extension with the proxy permission registered to receive <all_urls>, th...
When an extension with the proxy permission registered to receive , the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
Scope: local
sid: r
debian