Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 27 of 78
CVE-2023-29551P3HIGHCVSS 8.8fixed in firefox 112.0-1 (sid)2023
CVE-2023-29551 [HIGH] CVE-2023-29551: firefox - Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of...
Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Scope: local
sid: resolved (fixed in 112.0-1)
debian
CVE-2024-6615P3HIGHCVSS 8.8fixed in firefox 128.0-1 (sid)2024
CVE-2024-6615 [HIGH] CVE-2024-6615: firefox - Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bug...
Memory safety bugs present in Firefox 127 and Thunderbird 127. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128 and Thunderbird < 128.
Scope: local
sid: resolved (fixed in 128.0-1)
debian
CVE-2017-5398P3CRITICALCVSS 9.8fixed in firefox 52.0-1 (sid)2017
CVE-2017-5398 [CRITICAL] CVE-2017-5398: firefox - Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed ...
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Scope: local
sid: resolved (fixed in 52.0-1)
debian
CVE-2019-11716P3HIGHCVSS 8.3fixed in firefox 68.0-1 (sid)2019
CVE-2019-11716 [HIGH] CVE-2019-11716: firefox - Until explicitly accessed by script, window.globalThis is not enumerable and, as...
Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.
Scope: local
debian
CVE-2017-5400P3CRITICALCVSS 9.8fixed in firefox 52.0-1 (sid)2017
CVE-2017-5400 [CRITICAL] CVE-2017-5400: firefox - JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASL...
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Scope: local
sid: resolved (fixed in 52.0-1)
debian
CVE-2018-5154P3CRITICALCVSS 9.8fixed in firefox 60.0-1 (sid)2018
CVE-2018-5154 [CRITICAL] CVE-2018-5154: firefox - A use-after-free vulnerability can occur while enumerating attributes during SVG...
A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
Scope: local
sid: resolved (fixed in 60.0-1)
debian
CVE-2017-5376P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5376 [CRITICAL] CVE-2017-5376: firefox - Use-after-free while manipulating XSL in XSLT documents. This vulnerability affe...
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2018-5150P3CRITICALCVSS 9.8fixed in firefox 60.0-1 (sid)2018
CVE-2018-5150 [CRITICAL] CVE-2018-5150: firefox - Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbir...
Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
Scope: local
debian
CVE-2017-5435P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5435 [CRITICAL] CVE-2017-5435: firefox - A use-after-free vulnerability occurs during transaction processing in the edito...
A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2017-5432P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5432 [CRITICAL] CVE-2017-5432: firefox - A use-after-free vulnerability occurs during certain text input selection result...
A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2017-5446P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5446 [CRITICAL] CVE-2017-5446: firefox - An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames...
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2018-5099P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5099 [CRITICAL] CVE-2018-5099: firefox - A use-after-free vulnerability can occur when the widget listener is holding str...
A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been freed, resulting in a potentially exploitable crash when these references are used. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2018-5103P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5103 [CRITICAL] CVE-2018-5103: firefox - A use-after-free vulnerability can occur during mouse event handling due to issu...
A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2017-5441P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5441 [CRITICAL] CVE-2017-5441: firefox - A use-after-free vulnerability when holding a selection during scroll events. Th...
A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2017-5402P3CRITICALCVSS 9.8fixed in firefox 52.0-1 (sid)2017
CVE-2017-5402 [CRITICAL] CVE-2017-5402: firefox - A use-after-free can occur when events are fired for a "FontFace" object after t...
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
Scope: local
sid: resolved (fixed in 52.0-1)
debian
CVE-2024-2608P3HIGHCVSS 8.4fixed in firefox 124.0-1 (sid)2024
CVE-2024-2608 [HIGH] CVE-2024-2608: firefox - `AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEn...
`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Scope: local
sid: resolved (fixed in 124.0-1)
debian
CVE-2017-7750P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7750 [CRITICAL] CVE-2017-7750: firefox - A use-after-free vulnerability during video control operations when a "<track>" ...
A use-after-free vulnerability during video control operations when a "" element holds a reference to an older window if that window has been replaced in the DOM. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2018-5166P3HIGHCVSS 7.5fixed in firefox 60.0-1 (sid)2018
CVE-2018-5166 [HIGH] CVE-2018-5166: firefox - WebExtensions can use request redirection and a "filterReponseData" filter to by...
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.
Scope: local
sid: resolved (fixed in 60.0-1)
debian
CVE-2017-7756P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7756 [CRITICAL] CVE-2017-7756: firefox - A use-after-free and use-after-scope vulnerability when logging errors from head...
A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2017-5442P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5442 [CRITICAL] CVE-2017-5442: firefox - A use-after-free vulnerability during changes in style when manipulating DOM ele...
A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian