Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 25 of 78
CVE-2022-34476P3CRITICALCVSS 9.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34476 [CRITICAL] CVE-2022-34476: firefox - ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have re...
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.
Scope: local
sid: resolved (fixed in 102.0-1)
debian
CVE-2023-25736P3CRITICALCVSS 9.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25736 [CRITICAL] CVE-2023-25736: firefox - An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to und...
An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.
Scope: local
sid: resolved (fixed in 110.0-1)
debian
CVE-2024-8900P3HIGHCVSS 7.5fixed in firefox 129.0-1 (sid)2024
CVE-2024-8900 [HIGH] CVE-2024-8900: firefox - An attacker could write data to the user's clipboard, bypassing the user prompt,...
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
Scope: local
sid: resolved (fixed in 129.0-1)
debian
CVE-2024-5701P3CRITICALCVSS 9.8fixed in firefox 127.0-1 (sid)2024
CVE-2024-5701 [CRITICAL] CVE-2024-5701: firefox - Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of...
Memory safety bugs present in Firefox 126. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2016-9066P3HIGHCVSS 7.5fixed in firefox 50.0-1 (sid)2016
CVE-2016-9066 [HIGH] CVE-2016-9066: firefox - A buffer overflow resulting in a potentially exploitable crash due to memory all...
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2024-8389P3CRITICALCVSS 9.8fixed in firefox 130.0-1 (sid)2024
CVE-2024-8389 [CRITICAL] CVE-2024-8389: firefox - Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of...
Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130.
Scope: local
sid: resolved (fixed in 130.0-1)
debian
CVE-2016-1959P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1959 [HIGH] CVE-2016-1959: firefox - The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote atta...
The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2025-14332P3HIGHCVSS 7.3fixed in firefox 146.0-1 (sid)2025
CVE-2025-14332 [HIGH] CVE-2025-14332: firefox - Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bug...
Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146 and Thunderbird < 146.
Scope: local
sid: resolved (fixed in 146.0-1)
debian
CVE-2006-5633P4LOWCVSS 5.0PoCfixed in firefox 45.0-1 (sid)2006
CVE-2006-5633 [MEDIUM] CVE-2006-5633: firefox - Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a ...
Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was poss
debian
CVE-2020-6800P3HIGHCVSS 8.8fixed in firefox 73.0-1 (sid)2020
CVE-2020-6800 [HIGH] CVE-2020-6800: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product because script
debian
CVE-2016-1951P3HIGHCVSS 8.6fixed in firefox 45.0-1 (sid)2016
CVE-2016-1951 [HIGH] CVE-2016-1951: firefox - Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (N...
Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2021-38496P3HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-38496 [HIGH] CVE-2021-38496: firefox - During operations on MessageTasks, a task may have been removed while it was sti...
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
Scope: local
sid: resolved (fixed in 93.0-1)
debian
CVE-2019-11711P3HIGHCVSS 8.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11711 [HIGH] CVE-2019-11711: firefox - When an inner window is reused, it does not consider the use of document.domain ...
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerabil
debian
CVE-2020-15656P3HIGHCVSS 8.8fixed in firefox 79.0-1 (sid)2020
CVE-2020-15656 [HIGH] CVE-2020-15656: firefox - JIT optimizations involving the Javascript arguments object could confuse later ...
JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Scope: local
sid: resolved (fixed in 79.0-1)
debian
CVE-2021-29985P3HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29985 [HIGH] CVE-2021-29985: firefox - A use-after-free vulnerability in media channels could have led to memory corrup...
A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Scope: local
sid: resolved (fixed in 91.0-1)
debian
CVE-2021-29970P3HIGHCVSS 8.8fixed in firefox 90.0-1 (sid)2021
CVE-2021-29970 [HIGH] CVE-2021-29970: firefox - A malicious webpage could have triggered a use-after-free, memory corruption, an...
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when accessibility was enabled.*. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
Scope: local
sid: resolved (fixed in 90.0-1)
debian
CVE-2021-29984P3HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29984 [HIGH] CVE-2021-29984: firefox - Instruction reordering resulted in a sequence of instructions that would cause a...
Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Scope: local
sid: resolved (fixed in 91.0-1)
debian
CVE-2021-29967P3HIGHCVSS 8.8fixed in firefox 89.0-1 (sid)2021
CVE-2021-29967 [HIGH] CVE-2021-29967: firefox - Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
Scope: local
sid: resolved (fix
debian
CVE-2020-6805P3HIGHCVSS 8.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6805 [HIGH] CVE-2020-6805: firefox - When removing data about an origin whose tab was recently closed, a use-after-fr...
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Scope: local
sid: resolved (fixed in 74.0-1)
debian
CVE-2020-6807P3HIGHCVSS 8.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6807 [HIGH] CVE-2020-6807: firefox - When a device was changed while a stream was about to be destroyed, the <code>st...
When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
Scope: local
sid: resolved (fixed in 74.0-1)
debian