Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 22 of 78
CVE-2021-23978P3HIGHCVSS 8.8fixed in firefox 86.0-1 (sid)2021
CVE-2021-23978 [HIGH] CVE-2021-23978: firefox - Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
Scope: local
sid: resolved (fixed
debian
CVE-2020-26968P3HIGHCVSS 8.8fixed in firefox 83.0-1 (sid)2020
CVE-2020-26968 [HIGH] CVE-2020-26968: firefox - Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Scope: local
sid: resolved (fixed
debian
CVE-2021-23999P3HIGHCVSS 8.8fixed in firefox 88.0-1 (sid)2021
CVE-2021-23999 [HIGH] CVE-2021-23999: firefox - If a Blob URL was loaded through some unusual user interaction, it could have be...
If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2021-23964P3HIGHCVSS 8.8fixed in firefox 85.0-1 (sid)2021
CVE-2021-23964 [HIGH] CVE-2021-23964: firefox - Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
Scope: local
sid: resolved (fixed
debian
CVE-2021-43534P3HIGHCVSS 8.8fixed in firefox 94.0-1 (sid)2021
CVE-2021-43534 [HIGH] CVE-2021-43534: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
debian
CVE-2023-6859P3HIGHCVSS 8.8fixed in firefox 121.0-1 (sid)2023
CVE-2023-6859 [HIGH] CVE-2023-6859: firefox - A use-after-free condition affected TLS socket creation when under memory pressu...
A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Scope: local
sid: resolved (fixed in 121.0-1)
debian
CVE-2020-12406P3HIGHCVSS 8.8fixed in firefox 77.0-1 (sid)2020
CVE-2020-12406 [HIGH] CVE-2020-12406: firefox - Mozilla Developer Iain Ireland discovered a missing type check during unboxed ob...
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Scope: local
sid: resolved (fixed in 77.0-1)
debian
CVE-2022-38477P3HIGHCVSS 8.8fixed in firefox 104.0-1 (sid)2022
CVE-2022-38477 [HIGH] CVE-2022-38477: firefox - Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safe...
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.2, Thunderbird < 102.2, and Fir
debian
CVE-2022-22751P3HIGHCVSS 8.8fixed in firefox 96.0-1 (sid)2022
CVE-2022-22751 [HIGH] CVE-2022-22751: firefox - Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratz...
Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve Fink reported memory safety bugs present in Firefox 95 and Firefox ESR 91.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary
debian
CVE-2023-32215P3HIGHCVSS 8.8fixed in firefox 113.0-1 (sid)2023
CVE-2023-32215 [HIGH] CVE-2023-32215: firefox - Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily M...
Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112 and Firefox ESR 102.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to r
debian
CVE-2022-22761P3HIGHCVSS 8.8fixed in firefox 97.0-1 (sid)2022
CVE-2022-22761 [HIGH] CVE-2022-22761: firefox - Web-accessible extension pages (pages with a moz-extension:// scheme) were not c...
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Scope: local
sid: resolved (fixed in 97.0-1)
debian
CVE-2023-28176P3HIGHCVSS 8.8fixed in firefox 111.0-1 (sid)2023
CVE-2023-28176 [HIGH] CVE-2023-28176: firefox - Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these b...
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
Scope: local
sid: resolved (fixed in 111.0-1)
debian
CVE-2022-42932P3HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-42932 [HIGH] CVE-2022-42932: firefox - Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safe...
Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbi
debian
CVE-2023-29536P3HIGHCVSS 8.8fixed in firefox 112.0-1 (sid)2023
CVE-2023-29536 [HIGH] CVE-2023-29536: firefox - An attacker could cause the memory manager to incorrectly free a pointer that ad...
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
Scope: local
sid: resolved (
debian
CVE-2023-25737P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25737 [HIGH] CVE-2023-25737: firefox - An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> coul...
An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2022-22764P3HIGHCVSS 8.8fixed in firefox 97.0-1 (sid)2022
CVE-2022-22764 [HIGH] CVE-2022-22764: firefox - Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safe...
Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR <
debian
CVE-2022-38473P3HIGHCVSS 8.8fixed in firefox 104.0-1 (sid)2022
CVE-2022-38473 [HIGH] CVE-2022-38473: firefox - A cross-origin iframe referencing an XSLT document would inherit the parent doma...
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
Scope: local
sid: resolved (fixed in 104.0-1)
debian
CVE-2023-25739P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25739 [HIGH] CVE-2023-25739: firefox - Module load requests that failed were not being checked as to whether or not the...
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in ScriptLoadContext. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2023-25744P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25744 [HIGH] CVE-2023-25744: firefox - Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these ...
Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2024-0745P3HIGHCVSS 8.8fixed in firefox 122.0-1 (sid)2024
CVE-2024-0745 [HIGH] CVE-2024-0745: firefox - The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow....
The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.
Scope: local
sid: resolved (fixed in 122.0-1)
debian