cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 11 of 78
CVE-2025-9179P3CRITICALCVSS 9.8fixed in firefox 142.0-1 (sid)2025
CVE-2025-9179 [CRITICAL] CVE-2025-9179: firefox - An attacker was able to perform memory corruption in the GMP process which proce... An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and T
debian
CVE-2025-8028P3CRITICALCVSS 9.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8028 [CRITICAL] CVE-2025-8028: firefox - On arm64, a WASM `br_table` instruction with a lot of entries could lead to the ... On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. Scop
debian
CVE-2025-11709P3CRITICALCVSS 9.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11709 [CRITICAL] CVE-2025-11709: firefox - A compromised web process was able to trigger out of bounds reads and writes in ... A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4. Scope: local sid: resolved (fixed in 144.0-1)
debian
CVE-2026-4723P3CRITICALCVSS 9.8fixed in firefox 149.0-1 (sid)2026
CVE-2026-4723 [CRITICAL] CVE-2026-4723: firefox - Use-after-free in the JavaScript Engine component. This vulnerability affects Fi... Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 149 and Thunderbird < 149. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2025-13024P3CRITICALCVSS 9.8fixed in firefox 145.0-1 (sid)2025
CVE-2025-13024 [CRITICAL] CVE-2025-13024: firefox - JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability a... JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 145 and Thunderbird < 145. Scope: local sid: resolved (fixed in 145.0-1)
debian
CVE-2025-11721P3CRITICALCVSS 9.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11721 [CRITICAL] CVE-2025-11721: firefox - Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed ev... Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 144 and Thunderbird < 144. Scope: local sid: resolved (fixed in 144.0-1)
debian
CVE-2025-12380P3CRITICALCVSS 9.8fixed in firefox 144.0.2-1 (sid)2025
CVE-2025-12380 [CRITICAL] CVE-2025-12380: firefox - Starting with Firefox 142, it was possible for a compromised child process to tr... Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or browser process using WebGPU-related IPC calls. This may have been usable to escape the child process sandbox. This vulnerability affects Firefox < 144.0.2. Scope: local sid: resolved (fixed in 144.0.2-1)
debian
CVE-2020-6831P3CRITICALCVSS 9.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6831 [CRITICAL] CVE-2020-6831: chromium - A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC.... A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. Scope: local bookworm: resolved (fixed in 83.0.4103.83-1) bullseye: resolved (fixed in 83.0.4103.83-1) forky: resolved
debian
CVE-2020-15969P3HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15969 [HIGH] CVE-2020-15969: chromium - Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote... Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 87.0.4280.88-0.1) bullseye: resolved (fixed in 87.0.4280.88-0.1) forky: resolved (fixed in 87.0.4280.88-0.1) sid: resolved (fixed in 87.0.4280.88-0.1) trixie: resolved (fi
debian
CVE-2017-7778P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7778 [CRITICAL] CVE-2017-7778: firefox - A number of security vulnerabilities in the Graphite 2 library including out-of-... A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. Scope: local sid: resolved (fixed in 54.0-1)
debian
CVE-2016-5281P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5281 [CRITICAL] CVE-2016-5281: firefox - Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before... Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2026-2806P3CRITICALCVSS 9.1fixed in firefox 148.0-1 (sid)2026
CVE-2026-2806 [CRITICAL] CVE-2026-2806: firefox - Uninitialized memory in the Graphics: Text component. This vulnerability affects... Uninitialized memory in the Graphics: Text component. This vulnerability affects Firefox < 148 and Thunderbird < 148. Scope: local sid: resolved (fixed in 148.0-1)
debian
CVE-2020-15254P3HIGHCVSS 8.1fixed in firefox 82.0-1 (sid)2020
CVE-2020-15254 [HIGH] CVE-2020-15254: firefox - Crossbeam is a set of tools for concurrent programming. In crossbeam-channel bef... Crossbeam is a set of tools for concurrent programming. In crossbeam-channel before version 0.4.4, the bounded channel incorrectly assumes that `Vec::from_iter` has allocated capacity that same as the number of iterator elements. `Vec::from_iter` does not actually guarantee that and may allocate extra memory. The destructor of the `bounded` channel reconstructs `Vec
debian
CVE-2023-0767P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-0767 [HIGH] CVE-2023-0767: firefox - An attacker could construct a PKCS 12 cert bundle in such a way that could allow... An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. Scope: local sid: resolved (fixed in 110.0-1)
debian
CVE-2023-6207P3HIGHCVSS 8.8fixed in firefox 120.0-1 (sid)2023
CVE-2023-6207 [HIGH] CVE-2023-6207: firefox - Ownership mismanagement led to a use-after-free in ReadableByteStreams This vuln... Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. Scope: local sid: resolved (fixed in 120.0-1)
debian
CVE-2025-1011P3HIGHCVSS 8.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1011 [HIGH] CVE-2025-1011: firefox - A bug in WebAssembly code generation could have lead to a crash. It may have bee... A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135. Scope: local sid: resolved (fixed in 135.0-1)
debian
CVE-2024-7520P3HIGHCVSS 8.8fixed in firefox 129.0-1 (sid)2024
CVE-2024-7520 [HIGH] CVE-2024-7520: firefox - A type confusion bug in WebAssembly could be leveraged by an attacker to potenti... A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1. Scope: local sid: resolved (fixed in 129.0-1)
debian
CVE-2024-8382P3HIGHCVSS 8.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8382 [HIGH] CVE-2024-8382: firefox - Internal browser event interfaces were exposed to web content when privileged Ev... Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulner
debian
CVE-2016-9900P3HIGHCVSS 7.5fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9900 [HIGH] CVE-2016-9900: firefox - External resources that should be blocked when loaded by SVG images can bypass s... External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. Scope: local sid: resolved (fixed in 50.1.0-1)
debian
CVE-2026-0882P3HIGHCVSS 8.8fixed in firefox 147.0-1 (sid)2026
CVE-2026-0882 [HIGH] CVE-2026-0882: firefox - Use-after-free in the IPC component. This vulnerability affects Firefox < 147, F... Use-after-free in the IPC component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7. Scope: local sid: resolved (fixed in 147.0-1)
debian
Debian Firefox vulnerabilities | cvebase