Known vulnerabilities in firefox-esr (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:firefox-esr_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 755
Public exploits: 23
Known exploited (KEV): 11
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting firefox-esr (Debian package) firefox-esr (Debian package) is affected by 755 known vulnerabilities: 9 critical, 378 high, 243 medium, 125 low Critical High Medium Low

Vulnerabilities (755)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU146611 - Use After Free
CVE-2026-84122
CWE-416 High
No
No
140.15.0esr-1~deb13u1 01.09.2026 SB2026090144
SB2026090308
#VU146612 - Use After Free
CVE-2026-84124
CWE-416 High
No
No
140.15.0esr-1~deb13u1 01.09.2026 SB2026090144
SB2026090308
#VU146613 - Memory corruption
CVE-2026-84143
CWE-119 High
No
No
140.15.0esr-1~deb13u1 01.09.2026 SB2026090144
SB2026090308
#VU146610 - Memory corruption
CVE-2026-84145
CWE-119 High
No
No
140.15.0esr-1~deb13u1 01.09.2026 SB2026090144
SB2026090308
#VU146609 - NULL Pointer Dereference
CVE-2026-84131
CWE-476 High
No
No
140.15.0esr-1~deb13u1 01.09.2026 SB2026090144
SB2026090308
#VU146608 - Use After Free
CVE-2026-84121
CWE-416 High
No
No
140.15.0esr-1~deb13u1 01.09.2026 SB2026090144
SB2026090308
#VU146606 - Use After Free
CVE-2026-84119
CWE-416 High
No
No
140.15.0esr-1~deb13u1 01.09.2026 SB2026090144
SB2026090308
#VU146607 - Use After Free
CVE-2026-84120
CWE-416 High
No
No
140.15.0esr-1~deb13u1 01.09.2026 SB2026090144
SB2026090308
#VU144097 - Improper Access Control
CVE-2026-75874
CWE-284 High
No
No
140.15.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081989
SB2026082141
and 2 more
#VU144058 - Use After Free
CVE-2026-74936
CWE-416 High
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU144059 - Improper Privilege Management
CVE-2026-74941
CWE-269 High
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU144060 - Use After Free
CVE-2026-74944
CWE-416 High
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU144051 - Exposure of sensitive information to an unauthorized actor
CVE-2026-74945
CWE-200 Medium
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU144048 - Use After Free
CVE-2026-74940
CWE-416 High
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU144049 - Improper Access Control
CVE-2026-74942
CWE-284 High
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU144050 - Use After Free
CVE-2026-74943
CWE-416 High
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU144045 - Improper Access Control
CVE-2026-74934
CWE-284 Medium
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU144046 - Improper Access Control
CVE-2026-74935
CWE-284 High
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU144047 - Improper Access Control
CVE-2026-74939
CWE-284 High
No
No
140.14.0esr-1~deb13u1 18.08.2026 SB2026081838
SB2026081987
SB2026081988
and 16 more
#VU138995 - Improper Privilege Management
CVE-2026-16365
CWE-269 High
No
No
140.15.0esr-1~deb13u1 22.07.2026 SB2026072201
SB2026072302
SB2026090308


Showing elements 1 - 20 out of 755