cbcvebase.

Debian Firefox-Esr vulnerabilities

965 known vulnerabilities affecting debian/firefox-esr.

Total CVEs
965
CISA KEV
11
actively exploited
Public exploits
28
Exploited in wild
16
Severity breakdown
CRITICAL236HIGH418MEDIUM292LOW19

Vulnerabilities

Page 7 of 49
CVE-2025-10537P3HIGHCVSS 8.8fixed in firefox 143.0-1 (sid)2025
CVE-2025-10537 [HIGH] CVE-2025-10537: firefox - Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox ... Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3
debian
CVE-2022-46872P3HIGHCVSS 8.6fixed in firefox 108.0-1 (sid)2022
CVE-2022-46872 [HIGH] CVE-2022-46872: firefox - An attacker who compromised a content process could have partially escaped the s... An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6. Scope: local sid: resolved (fixed in 108.0-1)
debian
CVE-2018-18492P3CRITICALCVSS 9.8fixed in firefox 64.0-1 (sid)2018
CVE-2018-18492 [CRITICAL] CVE-2018-18492: firefox - A use-after-free vulnerability can occur after deleting a selection element due ... A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64. Scope: local sid: resolved (fixed in 64.0-1)
debian
CVE-2025-9185P3HIGHCVSS 8.1fixed in firefox 142.0-1 (sid)2025
CVE-2025-9185 [HIGH] CVE-2025-9185: firefox - Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbir... Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, F
debian
CVE-2026-0891P3HIGHCVSS 8.1fixed in firefox 147.0-1 (sid)2026
CVE-2026-0891 [HIGH] CVE-2026-0891: firefox - Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox ... Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
debian
CVE-2018-12387P3CRITICALCVSS 9.1fixed in firefox 62.0.3-1 (sid)2018
CVE-2018-12387 [CRITICAL] CVE-2018-12387: firefox - A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push w... A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2.2 and Firefox
debian
CVE-2018-18335P3HIGHCVSS 8.8fixed in chromium 71.0.3578.80-1 (bookworm)2018
CVE-2018-18335 [HIGH] CVE-2018-18335: chromium - Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a re... Heap buffer overflow in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 71.0.3578.80-1) bullseye: resolved (fixed in 71.0.3578.80-1) forky: resolved (fixed in 71.0.3578.80-1) sid: resolved (fixed in 71.0.3578.80-1) trixie: resolved (fixed
debian
CVE-2025-1016P3CRITICALCVSS 9.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1016 [CRITICAL] CVE-2025-1016: firefox - Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, ... Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Fi
debian
CVE-2025-9179P3CRITICALCVSS 9.8fixed in firefox 142.0-1 (sid)2025
CVE-2025-9179 [CRITICAL] CVE-2025-9179: firefox - An attacker was able to perform memory corruption in the GMP process which proce... An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and T
debian
CVE-2026-2762P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2762 [CRITICAL] CVE-2026-2762: firefox - Integer overflow in the JavaScript: Standard Library component. This vulnerabili... Integer overflow in the JavaScript: Standard Library component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8. Scope: local sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2774P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2774 [CRITICAL] CVE-2026-2774: firefox - Integer overflow in the Audio/Video component. This vulnerability affects Firefo... Integer overflow in the Audio/Video component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8. Scope: local sid: resolved (fixed in 148.0-1)
debian
CVE-2016-2811P3HIGHCVSS 8.8fixed in firefox 46.0-1 (sid)2016
CVE-2016-2811 [HIGH] CVE-2016-2811: firefox - Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worke... Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method. Scope: local sid: resolved (fixed in 46.0-1)
debian
CVE-2025-11709P3CRITICALCVSS 9.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11709 [CRITICAL] CVE-2025-11709: firefox - A compromised web process was able to trigger out of bounds reads and writes in ... A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4. Scope: local sid: resolved (fixed in 144.0-1)
debian
CVE-2020-6463P3HIGHCVSS 8.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6463 [HIGH] CVE-2020-6463: chromium - Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote... Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) forky: resolved (fixed in 83.0.4103.83-1) sid: resolved (fixed in 83.0.4103.83-1) trixie: resolved (fixed in 83.
debian
CVE-2026-2781P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2781 [CRITICAL] CVE-2026-2781: firefox - Integer overflow in the Libraries component in NSS. This vulnerability affects F... Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8. Scope: local sid: resolved (fixed in 148.0-1)
debian
CVE-2016-1962P3CRITICALCVSS 9.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1962 [CRITICAL] CVE-2016-1962: firefox - Use-after-free vulnerability in the mozilla::DataChannelConnection::Close functi... Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2021-24002P3HIGHCVSS 8.8fixed in firefox 88.0-1 (sid)2021
CVE-2021-24002 [HIGH] CVE-2021-24002: firefox - When a user clicked on an FTP URL containing encoded newline characters (%0A and... When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88. Scope: local sid: resolved (fixed in 88.0-1)
debian
CVE-2026-4715P3CRITICALCVSS 9.1fixed in firefox 149.0-1 (sid)2026
CVE-2026-4715 [CRITICAL] CVE-2026-4715: firefox - Uninitialized memory in the Graphics: Canvas2D component. This vulnerability aff... Uninitialized memory in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4716P3CRITICALCVSS 9.1fixed in firefox 149.0-1 (sid)2026
CVE-2026-4716 [CRITICAL] CVE-2026-4716: firefox - Incorrect boundary conditions, uninitialized memory in the JavaScript Engine com... Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2025-4083P3CRITICALCVSS 9.1fixed in firefox 138.0-1 (sid)2025
CVE-2025-4083 [CRITICAL] CVE-2025-4083: firefox - A process isolation vulnerability in Thunderbird stemmed from improper handling ... A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird <
debian
Debian Firefox-Esr vulnerabilities | cvebase