Debian Firefox-Esr vulnerabilities
1,071 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
1,071
CISA KEV
11
actively exploited
Public exploits
23
Exploited in wild
15
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW125
Vulnerabilities
Page 47 of 54
CVE-2016-1962CRITICALCVSS 9.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1962 [CRITICAL] CVE-2016-1962: firefox - Use-after-free vulnerability in the mozilla::DataChannelConnection::Close functi...
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-9898CRITICALCVSS 9.8fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9898 [CRITICAL] CVE-2016-9898: firefox - Use-after-free resulting in potentially exploitable crash when manipulating DOM ...
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2016-9899CRITICALCVSS 9.8PoCfixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9899 [CRITICAL] CVE-2016-9899: firefox - Use-after-free while manipulating DOM events and removing audio elements due to ...
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2016-5280CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5280 [CRITICAL] CVE-2016-5280: firefox - Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::Remove...
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2016-5257CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5257 [CRITICAL] CVE-2016-5257: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2016-1950HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1950 [HIGH] CVE-2016-1950: firefox - Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.1...
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-9078HIGHCVSS 8.8fixed in firefox 50.0.2-1 (sid)2016
CVE-2016-9078 [HIGH] CVE-2016-9078: firefox - Redirection from an HTTP connection to a "data:" URL assigns the referring site'...
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Firefox 49 and 50.
debian
CVE-2016-2796HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2796 [HIGH] CVE-2016-2796: firefox - Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in...
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2799HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2799 [HIGH] CVE-2016-2799: firefox - Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite ...
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2797HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2797 [HIGH] CVE-2016-2797: firefox - The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6...
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801.
Scope: local
sid: re
debian
CVE-2016-1979HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1979 [HIGH] CVE-2016-1979: firefox - Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey fun...
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-5264HIGHCVSS 8.8fixed in firefox 48.0-1 (sid)2016
CVE-2016-5264 [HIGH] CVE-2016-5264: firefox - Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange ...
Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG element that is mishandled during effect application.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2016-2812HIGHCVSS 7.5fixed in firefox 46.0-1 (sid)2016
CVE-2016-2812 [HIGH] CVE-2016-2812: firefox - Race condition in the get implementation in the ServiceWorkerManager class in th...
Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site.
Scope: local
sid: resolved (fixed in 46.0-1)
debian
CVE-2016-9894HIGHCVSS 7.5fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9894 [HIGH] CVE-2016-9894: firefox - A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocat...
A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buffer, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.1.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2016-2811HIGHCVSS 8.8fixed in firefox 46.0-1 (sid)2016
CVE-2016-2811 [HIGH] CVE-2016-2811: firefox - Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worke...
Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.
Scope: local
sid: resolved (fixed in 46.0-1)
debian
CVE-2016-1960HIGHCVSS 8.8PoCfixed in firefox 45.0-1 (sid)2016
CVE-2016-1960 [HIGH] CVE-2016-1960: firefox - Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in ...
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
Scope: local
sid: resolved (fix
debian
CVE-2016-2838HIGHCVSS 8.8fixed in firefox 48.0-1 (sid)2016
CVE-2016-2838 [HIGH] CVE-2016-2838: firefox - Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mo...
Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via directional content in an SVG document.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2016-2795HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2795 [HIGH] CVE-2016-2795: firefox - The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as us...
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (
debian
CVE-2016-2798HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2798 [HIGH] CVE-2016-2798: firefox - The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, a...
The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-9897HIGHCVSS 7.5fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9897 [HIGH] CVE-2016-9897: firefox - Memory corruption resulting in a potentially exploitable crash during WebGL func...
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian