Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 17 of 78
CVE-2023-4585P3HIGHCVSS 8.8fixed in firefox 117.0-1 (sid)2023
CVE-2023-4585 [HIGH] CVE-2023-4585: firefox - Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 11...
Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
Scope: local
sid: resolved (fixed in 11
debian
CVE-2023-37201P3HIGHCVSS 8.8fixed in firefox 115.0-1 (sid)2023
CVE-2023-37201 [HIGH] CVE-2023-37201: firefox - An attacker could have triggered a use-after-free condition when creating a WebR...
An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Scope: local
sid: resolved (fixed in 115.0-1)
debian
CVE-2023-37211P3HIGHCVSS 8.8fixed in firefox 115.0-1 (sid)2023
CVE-2023-37211 [HIGH] CVE-2023-37211: firefox - Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 1...
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Scope: local
sid: resolved (fixed
debian
CVE-2024-0755P3HIGHCVSS 8.8fixed in firefox 122.0-1 (sid)2024
CVE-2024-0755 [HIGH] CVE-2024-0755: firefox - Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 11...
Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Scope: local
sid: resolved (fixed in 12
debian
CVE-2023-25729P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25729 [HIGH] CVE-2023-25729: firefox - Permission prompts for opening external schemes were only shown for <code>Conten...
Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbir
debian
CVE-2026-0880P3HIGHCVSS 8.8fixed in firefox 147.0-1 (sid)2026
CVE-2026-0880 [HIGH] CVE-2026-0880: firefox - Sandbox escape due to integer overflow in the Graphics component. This vulnerabi...
Sandbox escape due to integer overflow in the Graphics component. This vulnerability affects Firefox < 147, Firefox ESR < 115.32, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
Scope: local
sid: resolved (fixed in 147.0-1)
debian
CVE-2023-3600P3HIGHCVSS 8.8fixed in firefox 115.0.2-1 (sid)2023
CVE-2023-3600 [HIGH] CVE-2023-3600: firefox - During the worker lifecycle, a use-after-free condition could have occurred, whi...
During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.
Scope: local
sid: resolved (fixed in 115.0.2-1)
debian
CVE-2024-6607P3HIGHCVSS 8.8fixed in firefox 128.0-1 (sid)2024
CVE-2024-6607 [HIGH] CVE-2024-6607: firefox - It was possible to prevent a user from exiting pointerlock when pressing escape ...
It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a ` ` element over certain permission prompts. This could be used to confuse a user into giving a site unintended permissions. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Scope: local
sid: resolved (fixed in 128.0-1)
debian
CVE-2024-4777P3HIGHCVSS 8.8fixed in firefox 126.0-1 (sid)2024
CVE-2024-4777 [HIGH] CVE-2024-4777: firefox - Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 1...
Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Scope: local
sid: resolved (fixed i
debian
CVE-2024-7528P3HIGHCVSS 8.8fixed in firefox 129.0-1 (sid)2024
CVE-2024-7528 [HIGH] CVE-2024-7528: firefox - Incorrect garbage collection interaction in IndexedDB could have led to a use-af...
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
Scope: local
sid: resolved (fixed in 129.0-1)
debian
CVE-2025-1010P3HIGHCVSS 8.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1010 [HIGH] CVE-2025-1010: firefox - An attacker could have caused a use-after-free via the Custom Highlight API, lea...
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Scope: local
sid: resolved (fixed in 135.0-1)
debian
CVE-2016-5270P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5270 [CRITICAL] CVE-2016-5270: firefox - Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString...
Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to cause a denial of service (boolean out-of-bounds write) or possibly have unspecified other impact via Unicode characters that are mishandled during text conversion.
debian
CVE-2026-5733P3HIGHCVSS 8.8fixed in firefox 149.0.2-1 (sid)2026
CVE-2026-5733 [HIGH] CVE-2026-5733: firefox - Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerabil...
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 149.0.2 and Thunderbird < 149.0.2.
Scope: local
sid: resolved (fixed in 149.0.2-1)
debian
CVE-2026-4690P3HIGHCVSS 8.6fixed in firefox 149.0-1 (sid)2026
CVE-2026-4690 [HIGH] CVE-2026-4690: firefox - Sandbox escape due to incorrect boundary conditions, integer overflow in the XPC...
Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2018-5156P3CRITICALCVSS 9.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-5156 [CRITICAL] CVE-2018-5156: firefox - A vulnerability can occur when capturing a media stream when the media source ty...
A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
Scope: local
sid: resolved (fixed in 61
debian
CVE-2026-24869P3HIGHCVSS 8.8fixed in firefox 147.0.2-1 (sid)2026
CVE-2026-24869 [HIGH] CVE-2026-24869: firefox - Use-after-free in the Layout: Scrolling and Overflow component. This vulnerabili...
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability affects Firefox < 147.0.2.
Scope: local
sid: resolved (fixed in 147.0.2-1)
debian
CVE-2017-5438P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5438 [CRITICAL] CVE-2017-5438: firefox - A use-after-free vulnerability during XSLT processing due to the result handler ...
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2026-4687P3HIGHCVSS 8.6fixed in firefox 149.0-1 (sid)2026
CVE-2026-4687 [HIGH] CVE-2026-4687: firefox - Sandbox escape due to incorrect boundary conditions in the Telemetry component. ...
Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2018-5094P3HIGHCVSS 7.5fixed in firefox 58.0-1 (sid)2018
CVE-2018-5094 [HIGH] CVE-2018-5094: firefox - A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElemen...
A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collection on memory that is now uninitialized. This results in a potentially exploitable crash. This vulnerability affects Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2018-12392P3CRITICALCVSS 9.8fixed in firefox 63.0-1 (sid)2018
CVE-2018-12392 [CRITICAL] CVE-2018-12392: firefox - When manipulating user events in nested loops while opening a document through s...
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
Scope: local
sid: resolved (fixed in 63.0-1)
debian