Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 20 of 78
CVE-2023-28162P3HIGHCVSS 8.8fixed in firefox 111.0-1 (sid)2023
CVE-2023-28162 [HIGH] CVE-2023-28162: firefox - While implementing AudioWorklets, some code may have casted one type to another,...
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Scope: local
sid: resolved (fixed in 111.0-1)
debian
CVE-2024-3856P3HIGHCVSS 8.8fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3856 [HIGH] CVE-2024-3856: firefox - A use-after-free could occur during WASM execution if garbage collection ran dur...
A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.
Scope: local
sid: resolved (fixed in 125.0.1-1)
debian
CVE-2024-9396P3HIGHCVSS 8.8fixed in firefox 131.0-1 (sid)2024
CVE-2024-9396 [HIGH] CVE-2024-9396: firefox - It is currently unknown if this issue is exploitable but a condition may arise w...
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Scope: local
sid: resolved (fixed in 131.0-1)
debian
CVE-2022-22755P3HIGHCVSS 8.8fixed in firefox 97.0-1 (sid)2022
CVE-2022-22755 [HIGH] CVE-2022-22755: firefox - By using XSL Transforms, a malicious webserver could have served a user an XSL d...
By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.
Scope: local
sid: resolved (fixed in 97.0-1)
debian
CVE-2023-25731P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25731 [HIGH] CVE-2023-25731: firefox - Due to URL previews in the network panel of developer tools improperly storing U...
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2024-9400P3HIGHCVSS 8.8fixed in firefox 131.0-1 (sid)2024
CVE-2024-9400 [HIGH] CVE-2024-9400: firefox - A potential memory corruption vulnerability could be triggered if an attacker ha...
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Scope: local
sid: resolved (fixed in 131.0-1)
debian
CVE-2018-5188P3CRITICALCVSS 9.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-5188 [CRITICAL] CVE-2018-5188: firefox - Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. ...
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
Scope:
debian
CVE-2026-5732P3HIGHCVSS 8.8fixed in firefox 149.0.2-1 (sid)2026
CVE-2026-5732 [HIGH] CVE-2026-5732: firefox - Incorrect boundary conditions, integer overflow in the Graphics: Text component....
Incorrect boundary conditions, integer overflow in the Graphics: Text component. This vulnerability affects Firefox < 149.0.2, Firefox ESR < 140.9.1, Thunderbird < 149.0.2, and Thunderbird < 140.9.1.
Scope: local
sid: resolved (fixed in 149.0.2-1)
debian
CVE-2017-5455P3HIGHCVSS 7.5fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5455 [HIGH] CVE-2017-5455: firefox - The internal feed reader APIs that crossed the sandbox barrier allowed for a san...
The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vulnerability that resulted in remote code execution inside the sandboxed process. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2026-2798P3HIGHCVSS 8.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2798 [HIGH] CVE-2026-2798: firefox - Use-after-free in the DOM: Core & HTML component. This vulnerability affects Fir...
Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2017-7824P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7824 [CRITICAL] CVE-2017-7824: firefox - A buffer overflow occurs when drawing and validating elements with the ANGLE gra...
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Scope: local
sid: resolved (fixed
debian
CVE-2017-5434P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5434 [CRITICAL] CVE-2017-5434: firefox - A use-after-free vulnerability occurs when redirecting focus handling which resu...
A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2017-5433P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5433 [CRITICAL] CVE-2017-5433: firefox - A use-after-free vulnerability in SMIL animation functions occurs when pointers ...
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in
debian
CVE-2017-5439P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5439 [CRITICAL] CVE-2017-5439: firefox - A use-after-free vulnerability during XSLT processing due to poor handling of te...
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2017-7784P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7784 [CRITICAL] CVE-2017-7784: firefox - A use-after-free vulnerability can occur when reading an image observer during f...
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2016-9898P3CRITICALCVSS 9.8fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9898 [CRITICAL] CVE-2016-9898: firefox - Use-after-free resulting in potentially exploitable crash when manipulating DOM ...
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2017-7818P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7818 [CRITICAL] CVE-2017-7818: firefox - A use-after-free vulnerability can occur when manipulating arrays of Accessible ...
A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
Scope: local
sid: resolved (fixed in 56.0-1)
debian
CVE-2018-5091P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5091 [CRITICAL] CVE-2018-5091: firefox - A use-after-free vulnerability can occur during WebRTC connections when interact...
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2017-5443P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5443 [CRITICAL] CVE-2017-5443: firefox - An out-of-bounds write vulnerability while decoding improperly formed BinHex for...
An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2020-15683P3CRITICALCVSS 9.8fixed in firefox 82.0-1 (sid)2020
CVE-2020-15683 [CRITICAL] CVE-2020-15683: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4, Firefox < 82, and Thunderbird < 78.4.
Scope: l
debian