Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 23 of 78
CVE-2024-7522P3HIGHCVSS 8.8fixed in firefox 129.0-1 (sid)2024
CVE-2024-7522 [HIGH] CVE-2024-7522: firefox - Editor code failed to check an attribute value. This could have led to an out-of...
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
Scope: local
sid: resolved (fixed in 129.0-1)
debian
CVE-2017-7786P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7786 [CRITICAL] CVE-2017-7786: firefox - A buffer overflow can occur when the image renderer attempts to paint non-displa...
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2023-4047P3HIGHCVSS 8.8fixed in firefox 116.0-1 (sid)2023
CVE-2023-4047 [HIGH] CVE-2023-4047: firefox - A bug in popup notifications delay calculation could have made it possible for a...
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
Scope: local
sid: resolved (fixed in 116.0-1)
debian
CVE-2023-37209P3HIGHCVSS 8.8fixed in firefox 115.0-1 (sid)2023
CVE-2023-37209 [HIGH] CVE-2023-37209: firefox - A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSe...
A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSessionHistoryEntry` object was freed and a reference to that object remained. This resulted in a potentially exploitable condition when the reference to that object was later reused. This vulnerability affects Firefox < 115.
Scope: local
sid: resolved (fixed in 115.0-1)
debian
CVE-2024-4770P3HIGHCVSS 8.8fixed in firefox 126.0-1 (sid)2024
CVE-2024-4770 [HIGH] CVE-2024-4770: firefox - When saving a page to PDF, certain font styles could have led to a potential use...
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
Scope: local
sid: resolved (fixed in 126.0-1)
debian
CVE-2024-7530P3HIGHCVSS 8.8fixed in firefox 129.0-1 (sid)2024
CVE-2024-7530 [HIGH] CVE-2024-7530: firefox - Incorrect garbage collection interaction could have led to a use-after-free. Thi...
Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
Scope: local
sid: resolved (fixed in 129.0-1)
debian
CVE-2016-5256P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5256 [CRITICAL] CVE-2016-5256: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2017-5429P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5429 [CRITICAL] CVE-2017-5429: firefox - Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52...
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Sco
debian
CVE-2018-12378P3CRITICALCVSS 9.8fixed in firefox 62.0-1 (sid)2018
CVE-2018-12378 [CRITICAL] CVE-2018-12378: firefox - A use-after-free vulnerability can occur when an IndexedDB index is deleted whil...
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Scope: local
sid: resolved (fixed in 62.0-1)
debian
CVE-2018-12377P3CRITICALCVSS 9.8fixed in firefox 62.0-1 (sid)2018
CVE-2018-12377 [CRITICAL] CVE-2018-12377: firefox - A use-after-free vulnerability can occur when refresh driver timers are refreshe...
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
Scope: local
sid: resolved (fixed in 62.0-1)
debian
CVE-2017-7792P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7792 [CRITICAL] CVE-2017-7792: firefox - A buffer overflow will occur when viewing a certificate in the certificate manag...
A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2017-5380P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5380 [CRITICAL] CVE-2017-5380: firefox - A potential use-after-free found through fuzzing during DOM manipulation of SVG ...
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2018-12395P3HIGHCVSS 7.5fixed in firefox 63.0-1 (sid)2018
CVE-2018-12395 [HIGH] CVE-2018-12395: firefox - By rewriting the Host: request headers using the webRequest API, a WebExtension ...
By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
Scope: local
sid: resolved (fixed in 63.0-1)
debian
CVE-2006-1730P3HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-1730 [CRITICAL] CVE-2006-1730: firefox - Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x...
Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.2-1)
debian
CVE-2018-5098P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5098 [CRITICAL] CVE-2018-5098: firefox - A use-after-free vulnerability can occur when form input elements, focus, and se...
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2017-7800P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7800 [CRITICAL] CVE-2017-7800: firefox - A use-after-free vulnerability can occur in WebSockets when the object holding t...
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2018-5148P3CRITICALCVSS 9.8fixed in firefox 59.0.2-1 (sid)2018
CVE-2018-5148 [CRITICAL] CVE-2018-5148: firefox - A use-after-free vulnerability can occur in the compositor during certain graphi...
A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.
Scope: local
sid: resolved (fixed in 59.0.2-1)
debian
CVE-2017-5430P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5430 [CRITICAL] CVE-2017-5430: firefox - Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird ...
Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0
debian
CVE-2018-5115P3HIGHCVSS 7.5fixed in firefox 58.0-1 (sid)2018
CVE-2018-5115 [HIGH] CVE-2018-5115: firefox - If an HTTP authentication prompt is triggered by a background network request fr...
If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the originating site of the authentication request and may cause users to mistakenly send private cred
debian
CVE-2017-7749P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7749 [CRITICAL] CVE-2017-7749: firefox - A use-after-free vulnerability when using an incorrect URL during the reloading ...
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
debian