Known vulnerabilities in firefox-esr (Debian package) 91.9.1esr-1~deb11u1

Vendor: Debian
Version: 91.9.1esr-1~deb11u1
Software CPE: cpe:2.3:o:debian:firefox-esr_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 7
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.7

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting firefox-esr (Debian package) version 91.9.1esr-1~deb11u1 firefox-esr (Debian package) 91.9.1esr-1~deb11u1 is affected by 7 vulnerabilities: 4 high, 2 medium, 1 low Critical High Medium Low

Vulnerabilities (7)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU63879 - Memory corruption
CVE-2022-31747
CWE-119 High
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63878 - Exposure of sensitive information to an unauthorized actor
CVE-2022-31742
CWE-200 Medium
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63877 - Use of Uninitialized Variable
CVE-2022-31741
CWE-457 High
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 40 more
#VU63876 - Memory corruption
CVE-2022-31740
CWE-119 High
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63874 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-31738
CWE-451 Medium
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63873 - Out-of-bounds write
CVE-2022-31737
CWE-787 High
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more
#VU63872 - Exposure of sensitive information to an unauthorized actor
CVE-2022-31736
CWE-200 Low
No
No
91.10.0esr-1~deb10u1, 91.10.0esr-1~deb11u1 31.05.2022 SB2022053116
SB2022053126
SB2022060107
and 33 more