Known vulnerabilities in firefox-esr (Debian package) 68.4.0esr-1~deb10u1

Vendor: Debian
Version: 68.4.0esr-1~deb10u1
Software CPE: cpe:2.3:o:debian:firefox-esr_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 143
Public exploits: 8
Known exploited (KEV): 5
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting firefox-esr (Debian package) version 68.4.0esr-1~deb10u1 firefox-esr (Debian package) 68.4.0esr-1~deb10u1 is affected by 143 vulnerabilities: 5 critical, 69 high, 49 medium, 20 low Critical High Medium Low

Vulnerabilities (143)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU63879 - Memory corruption
CVE-2022-31747
CWE-119 High
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63878 - Exposure of sensitive information to an unauthorized actor
CVE-2022-31742
CWE-200 Medium
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63877 - Use of Uninitialized Variable
CVE-2022-31741
CWE-457 High
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 40 more
#VU63876 - Memory corruption
CVE-2022-31740
CWE-119 High
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63874 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-31738
CWE-451 Medium
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63873 - Out-of-bounds write
CVE-2022-31737
CWE-787 High
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63872 - Exposure of sensitive information to an unauthorized actor
CVE-2022-31736
CWE-200 Low
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63502 - Improper input validation
CVE-2022-1529
CWE-20 High
No
No
91.9.1esr-1~deb10u1, 91.9.1esr-1~deb11u1 21.05.2022 SB2022052102
SB2022052103
SB2022052104
and 30 more
#VU63501 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-1802
CWE-94 High
Public exploit available
No
91.9.1esr-1~deb10u1, 91.9.1esr-1~deb11u1 21.05.2022 SB2022052102
SB2022052103
SB2022052104
and 32 more
#VU62763 - Memory corruption
CVE-2022-29917
CWE-119 High
No
No
91.9.0esr-1~deb10u1, 91.9.0esr-1~deb11u1 03.05.2022 SB2022050314
SB2022050425
SB2022050426
and 30 more
#VU62760 - Security Features
CVE-2022-29912
CWE-254 Low
No
No
91.9.0esr-1~deb10u1, 91.9.0esr-1~deb11u1 03.05.2022 SB2022050314
SB2022050425
SB2022050426
and 31 more
#VU62759 - Security Features
CVE-2022-29911
CWE-254 Medium
No
No
91.9.0esr-1~deb10u1, 91.9.0esr-1~deb11u1 03.05.2022 SB2022050314
SB2022050425
SB2022050426
and 31 more
#VU62758 - Exposure of sensitive information to an unauthorized actor
CVE-2022-29916
CWE-200 Low
No
No
91.9.0esr-1~deb10u1, 91.9.0esr-1~deb11u1 03.05.2022 SB2022050314
SB2022050425
SB2022050426
and 30 more
#VU62757 - Permissions, Privileges, and Access Controls
CVE-2022-29909
CWE-264 High
No
No
91.9.0esr-1~deb10u1, 91.9.0esr-1~deb11u1 03.05.2022 SB2022050314
SB2022050425
SB2022050426
and 30 more
#VU62756 - Insufficient UI Warning of Dangerous Operations
CVE-2022-29914
CWE-357 Medium
No
No
91.9.0esr-1~deb10u1, 91.9.0esr-1~deb11u1 03.05.2022 SB2022050314
SB2022050425
SB2022050426
and 30 more
#VU61895 - Resource exhaustion
CVE-2022-24713
CWE-400 Medium
No
No
91.8.0esr-1~deb10u1, 91.8.0esr-1~deb11u1 05.04.2022 SB2022040527
SB2022040526
SB2022040529
and 34 more
#VU61894 - Use After Free
CVE-2022-1196
CWE-416 High
No
No
91.8.0esr-1~deb10u1, 91.8.0esr-1~deb11u1 05.04.2022 SB2022040526
SB2022040529
SB2022040628
and 23 more
#VU61886 - Use After Free
CVE-2022-28282
CWE-416 High
Public exploit available
No
91.8.0esr-1~deb10u1, 91.8.0esr-1~deb11u1 05.04.2022 SB2022040526
SB2022040529
SB2022040628
and 24 more
#VU61885 - Out-of-bounds write
CVE-2022-28281
CWE-787 High
Public exploit available
No
91.8.0esr-1~deb10u1, 91.8.0esr-1~deb11u1 05.04.2022 SB2022040526
SB2022040529
SB2022040628
and 24 more
#VU61884 - Use After Free
CVE-2022-1097
CWE-416 High
No
No
91.8.0esr-1~deb10u1, 91.8.0esr-1~deb11u1 05.04.2022 SB2022040526
SB2022040529
SB2022040628
and 28 more


Showing elements 1 - 20 out of 143