Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 48 of 49
CVE-2016-1955P4MEDIUMCVSS 4.3fixed in firefox 45.0-1 (sid)2016
CVE-2016-1955 [MEDIUM] CVE-2016-1955: firefox - Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Po...
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2018-18511P4MEDIUMCVSS 4.3fixed in firefox 65.0.1-1 (sid)2018
CVE-2018-18511 [MEDIUM] CVE-2018-18511: firefox - Cross-origin images can be read from a canvas element in violation of the same-o...
Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.
Scope: local
sid: resolved (fixed in 65.0.1-1)
debian
CVE-2016-2830P4MEDIUMCVSS 4.3fixed in firefox 48.0-1 (sid)2016
CVE-2016-2830 [MEDIUM] CVE-2016-2830: firefox - Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the networ...
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the network connection used for favicon resource retrieval after the associated browser window is closed, which makes it easier for remote web servers to track users by observing network traffic from multiple IP addresses.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2020-12399P4MEDIUMCVSS 4.4fixed in firefox 77.0-1 (sid)2020
CVE-2020-12399 [MEDIUM] CVE-2020-12399: firefox - NSS has shown timing differences when performing DSA signatures, which was explo...
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Scope: local
sid: resolved (fixed in 77.0-1)
debian
CVE-2022-46877P4MEDIUMCVSS 4.3fixed in firefox 108.0-1 (sid)2022
CVE-2022-46877 [MEDIUM] CVE-2022-46877: firefox - By confusing the browser, the fullscreen notification could have been delayed or...
By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108.
Scope: local
sid: resolved (fixed in 108.0-1)
debian
CVE-2024-0749P4MEDIUMCVSS 4.3fixed in firefox 122.0-1 (sid)2024
CVE-2024-0749 [MEDIUM] CVE-2024-0749: firefox - A phishing site could have repurposed an `about:` dialog to show phishing conten...
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
Scope: local
sid: resolved (fixed in 122.0-1)
debian
CVE-2025-1935P4MEDIUMCVSS 4.3fixed in firefox 136.0-1 (sid)2025
CVE-2025-1935 [MEDIUM] CVE-2025-1935: firefox - A web page could trick a user into setting that site as the default handler for ...
A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8.
Scope: local
sid: resolved (fixed in 136.0-1)
debian
CVE-2025-5266P4MEDIUMCVSS 4.3fixed in firefox 139.0-1 (sid)2025
CVE-2025-5266 [MEDIUM] CVE-2025-5266: firefox - Script elements loading cross-origin resources generated load and error events w...
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
Scope: local
sid: resolved (fixed in 139.0-1)
debian
CVE-2025-5263P4MEDIUMCVSS 4.3fixed in firefox 139.0-1 (sid)2025
CVE-2025-5263 [MEDIUM] CVE-2025-5263: firefox - Error handling for script execution was incorrectly isolated from web content, w...
Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11.
Scope: local
sid: resolved (fixed in 139.0-1)
debian
CVE-2016-5250P4MEDIUMCVSS 4.3fixed in firefox 48.0-1 (sid)2016
CVE-2016-5250 [MEDIUM] CVE-2016-5250: firefox - Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow rem...
Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2016-1957P4MEDIUMCVSS 4.3fixed in firefox 45.0-1 (sid)2016
CVE-2016-1957 [MEDIUM] CVE-2016-1957: firefox - Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38....
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-5279P4MEDIUMCVSS 4.3fixed in firefox 49.0-1 (sid)2016
CVE-2016-5279 [MEDIUM] CVE-2016-5279: firefox - Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sens...
Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2016-5268P4MEDIUMCVSS 4.3fixed in firefox 48.0-1 (sid)2016
CVE-2016-5268 [MEDIUM] CVE-2016-5268: firefox - Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_...
Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2021-23968P4MEDIUMCVSS 4.3fixed in firefox 86.0-1 (sid)2021
CVE-2021-23968 [MEDIUM] CVE-2021-23968: firefox - If Content Security Policy blocked frame navigation, the full destination of a r...
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
Scope: local
sid: resolv
debian
CVE-2006-5464P4LOWCVSS 5.0fixed in firefox 45.0-1 (sid)2006
CVE-2006-5464 [MEDIUM] CVE-2006-5464: firefox - Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox bef...
Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2025-0240P4MEDIUMCVSS 4.0fixed in firefox 134.0-1 (sid)2025
CVE-2025-0240 [MEDIUM] CVE-2025-0240: firefox - Parsing a JavaScript module as JSON could, under some circumstances, cause cross...
Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
Scope: local
sid: resolved (fixed in 134.0-1)
debian
CVE-2024-3861P4MEDIUMCVSS 4.0fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3861 [MEDIUM] CVE-2024-3861: firefox - If an AlignedBuffer were assigned to itself, the subsequent self-move could resu...
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Scope: local
sid: resolved (fixed in 125.0.1-1)
debian
CVE-2006-6499P4HIGHCVSS 4.3fixed in firefox 45.0-1 (sid)2006
CVE-2006-6499 [MEDIUM] CVE-2006-6499: firefox - The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9...
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers to cause a denial of service via any plugins that reduce the precision.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2019-11743P4LOWCVSS 3.7fixed in firefox 69.0-1 (sid)2019
CVE-2019-11743 [LOW] CVE-2019-11743: firefox - Navigation events were not fully adhering to the W3C's "Navigation-Timing Level ...
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affects Firefox < 69,
debian
CVE-2025-0239P4MEDIUMCVSS 4.0fixed in firefox 134.0-1 (sid)2025
CVE-2025-0239 [MEDIUM] CVE-2025-0239: firefox - When using Alt-Svc, ALPN did not properly validate certificates when the origina...
When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
Scope: local
sid: resolved (fixed in 134.0-1)
debian