cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 13 of 78
CVE-2024-6602P3CRITICALCVSS 9.8fixed in firefox 128.0-1 (sid)2024
CVE-2024-6602 [CRITICAL] CVE-2024-6602: firefox - A mismatch between allocator and deallocator could have led to memory corruption... A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128. Scope: local sid: resolved (fixed in 128.0-1)
debian
CVE-2023-34416P3CRITICALCVSS 9.8fixed in firefox 114.0-1 (sid)2023
CVE-2023-34416 [CRITICAL] CVE-2023-34416: firefox - Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 1... Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12. Scope: local sid: resolved (f
debian
CVE-2022-46882P3CRITICALCVSS 9.8fixed in firefox 107.0-1 (sid)2022
CVE-2022-46882 [CRITICAL] CVE-2022-46882: firefox - A use-after-free in WebGL extensions could have led to a potentially exploitable... A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6. Scope: local sid: resolved (fixed in 107.0-1)
debian
CVE-2024-5699P3CRITICALCVSS 9.8fixed in firefox 127.0-1 (sid)2024
CVE-2024-5699 [CRITICAL] CVE-2024-5699: firefox - In violation of spec, cookie prefixes such as `__Secure` were being ignored if t... In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127. Scope: local sid: resolved (fixed in 1
debian
CVE-2024-8384P3CRITICALCVSS 9.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8384 [CRITICAL] CVE-2024-8384: firefox - The JavaScript garbage collector could mis-color cross-compartment objects if OO... The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15. Scope: local sid: resolved (fixed in 130.0-1)
debian
CVE-2025-49710P3CRITICALCVSS 9.8fixed in firefox 139.0.4-1 (sid)2025
CVE-2025-49710 [CRITICAL] CVE-2025-49710: firefox - An integer overflow was present in `OrderedHashTable` used by the JavaScript eng... An integer overflow was present in `OrderedHashTable` used by the JavaScript engine This vulnerability affects Firefox < 139.0.4. Scope: local sid: resolved (fixed in 139.0.4-1)
debian
CVE-2024-9393P3HIGHCVSS 7.5fixed in firefox 131.0-1 (sid)2024
CVE-2024-9393 [HIGH] CVE-2024-9393: firefox - An attacker could, via a specially crafted multipart response, execute arbitrary... An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability aff
debian
CVE-2016-5275P3HIGHCVSS 8.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5275 [HIGH] CVE-2016-5275: firefox - Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions f... Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2024-9402P3CRITICALCVSS 9.8fixed in firefox 131.0-1 (sid)2024
CVE-2024-9402 [CRITICAL] CVE-2024-9402: firefox - Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 12... Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131. Scope: local sid
debian
CVE-2024-8387P3CRITICALCVSS 9.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8387 [CRITICAL] CVE-2024-8387: firefox - Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 12... Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2. Scope: local sid: resolved (fixed i
debian
CVE-2024-5695P3CRITICALCVSS 9.8fixed in firefox 127.0-1 (sid)2024
CVE-2024-5695 [CRITICAL] CVE-2024-5695: firefox - If an out-of-memory condition occurs at a specific point using allocations in th... If an out-of-memory condition occurs at a specific point using allocations in the probabilistic heap checker, an assertion could have been triggered, and in rarer situations, memory corruption could have occurred. This vulnerability affects Firefox < 127. Scope: local sid: resolved (fixed in 127.0-1)
debian
CVE-2025-1020P3CRITICALCVSS 9.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1020 [CRITICAL] CVE-2025-1020: firefox - Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bug... Memory safety bugs present in Firefox 134 and Thunderbird 134. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135 and Thunderbird < 135. Scope: local sid: resolved (fixed in 135.0-1)
debian
CVE-2025-8044P3CRITICALCVSS 9.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8044 [CRITICAL] CVE-2025-8044: firefox - Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bug... Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141 and Thunderbird < 141. Scope: local sid: resolved (fixed in 141.0-1)
debian
CVE-2025-9187P3CRITICALCVSS 9.8fixed in firefox 142.0-1 (sid)2025
CVE-2025-9187 [CRITICAL] CVE-2025-9187: firefox - Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bug... Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 142 and Thunderbird < 142. Scope: local sid: resolved (fixed in 142.0-1)
debian
CVE-2026-2805P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2805 [CRITICAL] CVE-2026-2805: firefox - Invalid pointer in the DOM: Core & HTML component. This vulnerability affects Fi... Invalid pointer in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thunderbird < 148. Scope: local sid: resolved (fixed in 148.0-1)
debian
CVE-2025-11710P3CRITICALCVSS 9.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11710 [CRITICAL] CVE-2025-11710: firefox - A compromised web process using malicious IPC messages could have caused the pri... A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4. Scope: local sid: resolved (fixed in 144.0-1)
debian
CVE-2018-17466P3HIGHCVSS 8.8fixed in firefox 64.0-1 (sid)2018
CVE-2018-17466 [HIGH] CVE-2018-17466: firefox - Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allow... Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. Scope: local sid: resolved (fixed in 64.0-1)
debian
CVE-2025-6433P3CRITICALCVSS 9.8fixed in firefox 140.0-1 (sid)2025
CVE-2025-6433 [CRITICAL] CVE-2025-6433: firefox - If a user visited a webpage with an invalid TLS certificate, and granted an exce... If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140 and Thunderbird < 140. Scope: loca
debian
CVE-2025-8038P3CRITICALCVSS 9.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8038 [CRITICAL] CVE-2025-8038: firefox - Thunderbird ignored paths when checking the validity of navigations in a frame. ... Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1. Scope: local sid: resolved (fixed in 141.0-1)
debian
CVE-2016-9063P3CRITICALCVSS 9.8fixed in expat 2.2.0-2 (bookworm)2016
CVE-2016-9063 [CRITICAL] CVE-2016-9063: expat - An integer overflow during the parsing of XML using the Expat library. This vuln... An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50. Scope: local bookworm: resolved (fixed in 2.2.0-2) bullseye: resolved (fixed in 2.2.0-2) forky: resolved (fixed in 2.2.0-2) sid: resolved (fixed in 2.2.0-2) trixie: resolved (fixed in 2.2.0-2)
debian
Debian Firefox vulnerabilities | cvebase