Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 14 of 78
CVE-2016-5273P3HIGHCVSS 8.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5273 [HIGH] CVE-2016-5273: firefox - The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibi...
The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web site.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2019-11759P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11759 [HIGH] CVE-2019-11759: firefox - An attacker could have caused 4 bytes of HMAC output to be written past the end ...
An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
Scope: local
sid: resolved (fixed in 70.0-1)
debian
CVE-2017-5448P3HIGHCVSS 8.6fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5448 [HIGH] CVE-2017-5448: firefox - An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-enc...
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerabi
debian
CVE-2023-6861P3HIGHCVSS 8.8fixed in firefox 121.0-1 (sid)2023
CVE-2023-6861 [HIGH] CVE-2023-6861: firefox - The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflo...
The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
debian
CVE-2020-6822P3HIGHCVSS 8.8fixed in firefox 75.0-1 (sid)2020
CVE-2020-6822 [HIGH] CVE-2020-6822: firefox - On 32-bit builds, an out of bounds write could have occurred when processing an ...
On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
Scope: local
sid: resolved (fixed in 75.0-1)
debian
CVE-2025-0242P3MEDIUMCVSS 6.5fixed in firefox 134.0-1 (sid)2025
CVE-2025-0242 [MEDIUM] CVE-2025-0242: firefox - Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, ...
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Firef
debian
CVE-2022-1919P3HIGHCVSS 8.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-1919 [HIGH] CVE-2022-1919: firefox - Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remot...
Use after free in Codecs in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
sid: resolved (fixed in 101.0-1)
debian
CVE-2024-0750P3HIGHCVSS 8.8fixed in firefox 122.0-1 (sid)2024
CVE-2024-0750 [HIGH] CVE-2024-0750: firefox - A bug in popup notifications delay calculation could have made it possible for a...
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Scope: local
sid: resolved (fixed in 122.0-1)
debian
CVE-2023-4584P3HIGHCVSS 8.8fixed in firefox 117.0-1 (sid)2023
CVE-2023-4584 [HIGH] CVE-2023-4584: firefox - Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1...
Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Th
debian
CVE-2023-6208P3HIGHCVSS 8.8fixed in firefox 120.0-1 (sid)2023
CVE-2023-6208 [HIGH] CVE-2023-6208: firefox - When using X11, text selected by the page using the Selection API was erroneousl...
When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Scope: local
sid: resolved (fixed in 120.0-1)
debian
CVE-2023-29541P3HIGHCVSS 8.8fixed in firefox 112.0-1 (sid)2023
CVE-2023-29541 [HIGH] CVE-2023-29541: firefox - Firefox did not properly handle downloads of files ending in <code>.desktop</cod...
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Andro
debian
CVE-2024-11699P3HIGHCVSS 8.8fixed in firefox 133.0-1 (sid)2024
CVE-2024-11699 [HIGH] CVE-2024-11699: firefox - Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 12...
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Scope: local
sid:
debian
CVE-2024-0751P3HIGHCVSS 8.8fixed in firefox 122.0-1 (sid)2024
CVE-2024-0751 [HIGH] CVE-2024-0751: firefox - A malicious devtools extension could have been used to escalate privileges. This...
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Scope: local
sid: resolved (fixed in 122.0-1)
debian
CVE-2024-7521P3HIGHCVSS 8.8fixed in firefox 129.0-1 (sid)2024
CVE-2024-7521 [HIGH] CVE-2024-7521: firefox - Incomplete WebAssembly exception handing could have led to a use-after-free. Thi...
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Scope: local
sid: resolved (fixed in 129.0-1)
debian
CVE-2024-7527P3HIGHCVSS 8.8fixed in firefox 129.0-1 (sid)2024
CVE-2024-7527 [HIGH] CVE-2024-7527: firefox - Unexpected marking work at the start of sweeping could have led to a use-after-f...
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Scope: local
sid: resolved (fixed in 129.0-1)
debian
CVE-2024-10467P3HIGHCVSS 8.8fixed in firefox 132.0-1 (sid)2024
CVE-2024-10467 [HIGH] CVE-2024-10467: firefox - Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 12...
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Scope: local
sid:
debian
CVE-2016-5274P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5274 [CRITICAL] CVE-2016-5274: firefox - Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function i...
Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between restyling and the Web Animations model implementation.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2024-5696P3HIGHCVSS 8.6fixed in firefox 127.0-1 (sid)2024
CVE-2024-5696 [HIGH] CVE-2024-5696: firefox - By manipulating the text in an `<input>` tag, an attacker could have cause...
By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2025-11152P3HIGHCVSS 8.6fixed in firefox 143.0.3-1 (sid)2025
CVE-2025-11152 [HIGH] CVE-2025-11152: firefox - Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This...
Sandbox escape due to integer overflow in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143.0.3.
Scope: local
sid: resolved (fixed in 143.0.3-1)
debian
CVE-2017-5428P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5428 [CRITICAL] CVE-2017-5428: firefox - An integer overflow in "createImageBitmap()" was reported through the Pwn2Own co...
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.
debian