Debian Firefox-Esr vulnerabilities
965 known vulnerabilities affecting debian/firefox-esr.
Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19
Vulnerabilities
Page 49 of 49
CVE-2024-3302P4LOWCVSS 3.7fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3302 [LOW] CVE-2024-3302: firefox - There was no limit to the number of HTTP/2 CONTINUATION frames that would be pro...
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
Scope: local
sid: resolved (fixed in 125.0.1-1)
debian
CVE-2025-13015P4LOWCVSS 3.4fixed in firefox 145.0-1 (sid)2025
CVE-2025-13015 [LOW] CVE-2025-13015: firefox - Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR...
Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2023-34414P4LOWCVSS 3.1fixed in firefox 114.0-1 (sid)2023
CVE-2023-34414 [LOW] CVE-2023-34414: firefox - The error page for sites with invalid TLS certificates was missing the activatio...
The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks that exploit human response time delays. If a malicious page elicited user clicks in precise locations immediately before navigating to a site with a certificate error and made the renderer extremely busy at the s
debian
CVE-2024-2616P4LOWCVSS 2.7fixed in firefox-esr 115.9.0esr-1~deb12u1 (bookworm)2024
CVE-2024-2616 [LOW] CVE-2024-2616: firefox-esr - To harden ICU against exploitation, the behavior for out-of-memory conditions wa...
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR < 115.9 and Thunderbird < 115.9.
Scope: local
bookworm: resolved (fixed in 115.9.0esr-1~deb12u1)
bullseye: resolved (fixed in 115.9.0esr-1~deb11u1)
forky: resolved (fixed in 115.9.0esr-1)
sid: reso
debian
CVE-2017-5387P4LOWCVSS 3.3fixed in firefox 51.0-1 (sid)2017
CVE-2017-5387 [LOW] CVE-2017-5387: firefox - The existence of a specifically requested local file can be found due to the dou...
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "" tag refers to a file that does not exist if the source page is loaded locally. This vulnerability affects Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
← Previous49 / 49