Known vulnerabilities in firefox-esr (Debian package) 52.8.0esr-1~deb9u1

Vendor: Debian
Version: 52.8.0esr-1~deb9u1
Software CPE: cpe:2.3:o:debian:firefox-esr_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 19
Public exploits: 1
Known exploited (KEV): 3
Highest CVSSv4 Score: 8.7

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting firefox-esr (Debian package) version 52.8.0esr-1~deb9u1 firefox-esr (Debian package) 52.8.0esr-1~deb9u1 is affected by 19 vulnerabilities: 3 critical, 8 high, 3 medium, 5 low Critical High Medium Low

Vulnerabilities (19)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU26653 - Memory corruption
CVE-2020-6825
CWE-119 High
No
No
68.7.0esr-1~deb9u1, 68.7.0esr-1~deb10u1 07.04.2020 SB2020040743
SB2020040744
SB2020040748
and 25 more
#VU26650 - Out-of-bounds write
CVE-2020-6822
CWE-787 High
No
No
68.7.0esr-1~deb9u1, 68.7.0esr-1~deb10u1 07.04.2020 SB2020040743
SB2020040744
SB2020040748
and 24 more
#VU26649 - Out-of-bounds read
CVE-2020-6821
CWE-125 Medium
No
No
68.7.0esr-1~deb9u1, 68.7.0esr-1~deb10u1 07.04.2020 SB2020040743
SB2020040744
SB2020040748
and 26 more
#VU26574 - Use After Free
CVE-2020-6820
CWE-416 Critical
No
Exploited
68.6.1esr-1~deb9u1, 68.6.1esr-1~deb10u1 03.04.2020 SB2020040320
SB2020040401
SB2020040402
and 25 more
#VU26573 - Use After Free
CVE-2020-6819
CWE-416 Critical
No
Exploited
68.6.1esr-1~deb9u1, 68.6.1esr-1~deb10u1 03.04.2020 SB2020040320
SB2020040401
SB2020040402
and 25 more
#VU18824 - Type confusion
CVE-2019-11707
CWE-843 Critical
Public exploit available
Exploited
60.7.1esr-1~deb9u1 18.06.2019 SB2019061805
SB2019061904
SB2019061905
and 21 more
#VU18572 - Out-of-bounds read
CVE-2019-5798
CWE-125 Low
No
No
60.7.0esr-1~deb9u1 22.05.2019 SB2019052204
SB2019052212
SB2019052401
and 13 more
#VU18568 - Memory corruption
CVE-2019-9800
CWE-119 High
No
No
60.7.0esr-1~deb9u1 22.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18563 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2019-11698
CWE-451 Low
No
No
60.7.0esr-1~deb9u1 22.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18558 - Memory corruption
CVE-2019-11693
CWE-119 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18557 - Use After Free
CVE-2019-11692
CWE-416 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18556 - Use After Free
CVE-2019-11691
CWE-416 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18554 - Use After Free
CVE-2019-9820
CWE-416 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 18 more
#VU18553 - Improper input validation
CVE-2019-9819
CWE-20 High
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18551 - Permissions, Privileges, and Access Controls
CVE-2019-9817
CWE-264 Medium
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 19 more
#VU18550 - Type confusion
CVE-2019-9816
CWE-843 Medium
No
No
60.7.0esr-1~deb9u1 21.05.2019 SB2019052103
SB2019052104
SB2019052201
and 16 more
#VU18036 - Permissions, Privileges, and Access Controls
CVE-2019-9797
CWE-264 Low
No
No
60.7.0esr-1~deb9u1 21.03.2019 SB2019032101
SB2019032603
SB2019032806
and 17 more
#VU17708 - Use After Free
CVE-2019-7317
CWE-416 Low
No
No
60.7.0esr-1~deb9u1 14.02.2019 SB2019011606
SB2019041812
SB2019042401
and 46 more
#VU17654 - Permissions, Privileges, and Access Controls
CVE-2018-18511
CWE-264 Low
No
No
60.7.0esr-1~deb9u1 13.02.2019 SB2019021322
SB2019021408
SB2019022701
and 16 more