Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 12 of 78
CVE-2026-2769P3HIGHCVSS 8.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2769 [HIGH] CVE-2026-2769: firefox - Use-after-free in the Storage: IndexedDB component. This vulnerability affects F...
Use-after-free in the Storage: IndexedDB component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2025-14323P3HIGHCVSS 8.8fixed in firefox 146.0-1 (sid)2025
CVE-2025-14323 [HIGH] CVE-2025-14323: firefox - Privilege escalation in the DOM: Notifications component. This vulnerability aff...
Privilege escalation in the DOM: Notifications component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
Scope: local
sid: resolved (fixed in 146.0-1)
debian
CVE-2018-5163P3HIGHCVSS 8.1fixed in firefox 60.0-1 (sid)2018
CVE-2018-5163 [HIGH] CVE-2018-5163: firefox - If a malicious attacker has used another vulnerability to gain full control over...
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping
debian
CVE-2026-4722P3HIGHCVSS 8.8fixed in firefox 149.0-1 (sid)2026
CVE-2026-4722 [HIGH] CVE-2026-4722: firefox - Privilege escalation in the IPC component. This vulnerability affects Firefox < ...
Privilege escalation in the IPC component. This vulnerability affects Firefox < 149 and Thunderbird < 149.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2025-8040P3HIGHCVSS 8.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8040 [HIGH] CVE-2025-8040: firefox - Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox ...
Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.
debian
CVE-2025-13014P3HIGHCVSS 8.8fixed in firefox 145.0-1 (sid)2025
CVE-2025-13014 [HIGH] CVE-2025-13014: firefox - Use-after-free in the Audio/Video component. This vulnerability affects Firefox ...
Use-after-free in the Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Firefox ESR < 115.30, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2025-13020P3HIGHCVSS 8.8fixed in firefox 145.0-1 (sid)2025
CVE-2025-13020 [HIGH] CVE-2025-13020: firefox - Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects ...
Use-after-free in the WebRTC: Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2024-4771P3HIGHCVSS 8.6fixed in firefox 126.0-1 (sid)2024
CVE-2024-4771 [HIGH] CVE-2024-4771: firefox - A memory allocation check was missing which would lead to a use-after-free if th...
A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.
Scope: local
sid: resolved (fixed in 126.0-1)
debian
CVE-2018-5122P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5122 [CRITICAL] CVE-2018-5122: firefox - A potential integer overflow in the "DoCrypt" function of WebCrypto was identifi...
A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting it, it could result in an out-of-bounds write. This vulnerability affects Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2024-5688P3HIGHCVSS 8.1fixed in firefox 127.0-1 (sid)2024
CVE-2024-5688 [HIGH] CVE-2024-5688: firefox - If a garbage collection was triggered at the right time, a use-after-free could ...
If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2019-11693P3CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11693 [CRITICAL] CVE-2019-11693: firefox - The bufferdata function in WebGL is vulnerable to a buffer overflow with specifi...
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox
debian
CVE-2025-3030P3HIGHCVSS 8.1fixed in firefox 137.0-1 (sid)2025
CVE-2025-3030 [HIGH] CVE-2025-3030: firefox - Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, a...
Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.
Sco
debian
CVE-2025-9184P3HIGHCVSS 8.1fixed in firefox 142.0-1 (sid)2025
CVE-2025-9184 [HIGH] CVE-2025-9184: firefox - Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox ...
Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142, Firefox ESR < 140.2, Thunderbird < 142, and Thunderbird < 140.2.
debian
CVE-2016-5278P3HIGHCVSS 8.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5278 [HIGH] CVE-2016-5278: firefox - Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozill...
Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2016-1968P3HIGHCVSS 8.8fixed in brotli 0.3.0+dfsg-3 (bookworm)2016
CVE-2016-1968 [HIGH] CVE-2016-1968: brotli - Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remo...
Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.
Scope: local
bookworm: resolved (fixed in 0.3.0+dfsg-3)
bullseye: resolved (fixed in 0.3.0+dfsg-3)
forky: resolved (fixed in 0.3.0+dfsg-3)
sid: resolved (fixed in
debian
CVE-2019-11692P3CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11692 [CRITICAL] CVE-2019-11692: firefox - A use-after-free vulnerability can occur when listeners are removed from the eve...
A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Scope: local
sid: resolved (fixed in 67.0-2)
debian
CVE-2018-5097P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5097 [CRITICAL] CVE-2018-5097: firefox - A use-after-free vulnerability can occur during XSL transformations when the sou...
A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2018-5102P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5102 [CRITICAL] CVE-2018-5102: firefox - A use-after-free vulnerability can occur when manipulating HTML media elements w...
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2022-34470P3CRITICALCVSS 9.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34470 [CRITICAL] CVE-2022-34470: firefox - Session history navigations may have led to a use-after-free and potentially exp...
Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Scope: local
sid: resolved (fixed in 102.0-1)
debian
CVE-2022-31736P3CRITICALCVSS 9.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31736 [CRITICAL] CVE-2022-31736: firefox - A malicious website could have learned the size of a cross-origin resource that ...
A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
Scope: local
sid: resolved (fixed in 101.0-1)
debian