Known vulnerabilities in firefox-esr (Debian package) 52.7.0esr-1~deb9u1

Vendor: Debian
Version: 52.7.0esr-1~deb9u1
Software CPE: cpe:2.3:o:debian:firefox-esr_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 24
Public exploits: 1
Known exploited (KEV): 3
Highest CVSSv4 Score: 8.7

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting firefox-esr (Debian package) version 52.7.0esr-1~deb9u1 firefox-esr (Debian package) 52.7.0esr-1~deb9u1 is affected by 24 vulnerabilities: 3 critical, 10 high, 5 medium, 6 low Critical High Medium Low

Vulnerabilities (24)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU29457 - Improper Certificate Validation
CVE-2020-12421
CWE-295 Low
No
No
68.10.0esr-1~deb9u1, 68.10.0esr-1~deb10u1 02.07.2020 SB2020070208
SB2020070222
SB2020070301
and 24 more
#VU29456 - Use After Free
CVE-2020-12420
CWE-416 High
No
No
68.10.0esr-1~deb9u1, 68.10.0esr-1~deb10u1 02.07.2020 SB2020070208
SB2020070222
SB2020070301
and 24 more
#VU29455 - Use After Free
CVE-2020-12419
CWE-416 High
No
No
68.10.0esr-1~deb9u1, 68.10.0esr-1~deb10u1 02.07.2020 SB2020070208
SB2020070222
SB2020070301
and 24 more
#VU29453 - Out-of-bounds read
CVE-2020-12418
CWE-125 Medium
No
No
68.10.0esr-1~deb9u1, 68.10.0esr-1~deb10u1 02.07.2020 SB2020070208
SB2020070222
SB2020070301
and 24 more
#VU29452 - Improper input validation
CVE-2020-12417
CWE-20 Medium
No
No
68.10.0esr-1~deb9u1, 68.10.0esr-1~deb10u1 02.07.2020 SB2020070208
SB2020070222
SB2020070301
and 22 more
#VU26653 - Memory corruption
CVE-2020-6825
CWE-119 High
No
No
68.7.0esr-1~deb9u1, 68.7.0esr-1~deb10u1 07.04.2020 SB2020040743
SB2020040744
SB2020040748
and 25 more
#VU26650 - Out-of-bounds write
CVE-2020-6822
CWE-787 High
No
No
68.7.0esr-1~deb9u1, 68.7.0esr-1~deb10u1 07.04.2020 SB2020040743
SB2020040744
SB2020040748
and 24 more
#VU26649 - Out-of-bounds read
CVE-2020-6821
CWE-125 Medium
No
No
68.7.0esr-1~deb9u1, 68.7.0esr-1~deb10u1 07.04.2020 SB2020040743
SB2020040744
SB2020040748
and 26 more
#VU26574 - Use After Free
CVE-2020-6820
CWE-416 Critical
No
Exploited
68.6.1esr-1~deb9u1, 68.6.1esr-1~deb10u1 03.04.2020 SB2020040320
SB2020040401
SB2020040402
and 25 more
#VU26573 - Use After Free
CVE-2020-6819
CWE-416 Critical
No
Exploited
68.6.1esr-1~deb9u1, 68.6.1esr-1~deb10u1 03.04.2020 SB2020040320
SB2020040401
SB2020040402
and 25 more
#VU18824 - Type confusion
CVE-2019-11707
CWE-843 Critical
Public exploit available
Exploited
60.7.1esr-1~deb9u1 18.06.2019 SB2019061805
SB2019061904
SB2019061905
and 21 more
#VU18563 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2019-11698
CWE-451 Low
No
No
60.7.0esr-1~deb9u1 22.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18558 - Memory corruption
CVE-2019-11693
CWE-119 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18557 - Use After Free
CVE-2019-11692
CWE-416 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18556 - Use After Free
CVE-2019-11691
CWE-416 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18554 - Use After Free
CVE-2019-9820
CWE-416 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 18 more
#VU18553 - Improper input validation
CVE-2019-9819
CWE-20 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18551 - Permissions, Privileges, and Access Controls
CVE-2019-9817
CWE-264 Medium
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18550 - Type confusion
CVE-2019-9816
CWE-843 Medium
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 16 more
#VU17654 - Permissions, Privileges, and Access Controls
CVE-2018-18511
CWE-264 Low
No
No
60.7.0esr-1~deb9u1 13.02.2019 SB2019021322
SB2019021408
SB2019022701
and 16 more


Showing elements 1 - 20 out of 24