Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 28 of 78
CVE-2017-5472P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-5472 [CRITICAL] CVE-2017-5472: firefox - A use-after-free vulnerability with the frameloader during tree reconstruction w...
A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no longer exists. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2019-11709P3CRITICALCVSS 9.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11709 [CRITICAL] CVE-2019-11709: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: loc
debian
CVE-2006-1728P3HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-1728 [CRITICAL] CVE-2006-1728: firefox - Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 ...
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.2-1)
debian
CVE-2025-13017P3HIGHCVSS 8.1fixed in firefox 145.0-1 (sid)2025
CVE-2025-13017 [HIGH] CVE-2025-13017: firefox - Same-origin policy bypass in the DOM: Notifications component. This vulnerabilit...
Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2025-13019P3HIGHCVSS 8.1fixed in firefox 145.0-1 (sid)2025
CVE-2025-13019 [HIGH] CVE-2025-13019: firefox - Same-origin policy bypass in the DOM: Workers component. This vulnerability affe...
Same-origin policy bypass in the DOM: Workers component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, Thunderbird < 145, and Thunderbird < 140.5.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2020-6825P3CRITICALCVSS 9.8fixed in firefox 75.0-1 (sid)2020
CVE-2020-6825 [CRITICAL] CVE-2020-6825: firefox - Mozilla developers and community members Tyson Smith and Christian Holler report...
Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR <
debian
CVE-2025-14322P3HIGHCVSS 8.0fixed in firefox 146.0-1 (sid)2025
CVE-2025-14322 [HIGH] CVE-2025-14322: firefox - Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL...
Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability affects Firefox < 146, Firefox ESR < 115.31, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
Scope: local
sid: resolved (fixed in 146.0-1)
debian
CVE-2018-5128P3CRITICALCVSS 9.8fixed in firefox 59.0-1 (sid)2018
CVE-2018-5128 [CRITICAL] CVE-2018-5128: firefox - A use-after-free vulnerability can occur when manipulating elements, events, and...
A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in a potentially exploitable crash. This vulnerability affects Firefox < 59.
Scope: local
sid: resolved (fixed in 59.0-1)
debian
CVE-2018-5092P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5092 [CRITICAL] CVE-2018-5092: firefox - A use-after-free vulnerability can occur when the thread for a Web Worker is fre...
A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the main thread while cancelling fetch operations. This vulnerability affects Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2025-59375P3HIGHCVSS 7.5fixed in expat 2.7.2-1 (forky)2025
CVE-2025-59375 [HIGH] CVE-2025-59375: expat - libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory ...
libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.7.2-1)
sid: resolved (fixed in 2.7.2-1)
trixie: open
debian
CVE-2025-0241P3HIGHCVSS 7.7fixed in firefox 134.0-1 (sid)2025
CVE-2025-0241 [HIGH] CVE-2025-0241: firefox - When segmenting specially crafted text, segmentation would corrupt memory leadin...
When segmenting specially crafted text, segmentation would corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
Scope: local
sid: resolved (fixed in 134.0-1)
debian
CVE-2018-12362P3HIGHCVSS 8.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-12362 [HIGH] CVE-2018-12362: firefox - An integer overflow can occur during graphics operations done by the Supplementa...
An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
Scope: local
sid: resolved (fixed in 61.0-1)
debian
CVE-2024-10466P3HIGHCVSS 7.5fixed in firefox 132.0-1 (sid)2024
CVE-2024-10466 [HIGH] CVE-2024-10466: firefox - By sending a specially crafted push message, a remote server could have hung the...
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
Scope: local
sid: resolved (fixed in 132.0-1)
debian
CVE-2023-5731P3CRITICALCVSS 9.8fixed in firefox 119.0-1 (sid)2023
CVE-2023-5731 [CRITICAL] CVE-2023-5731: firefox - Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of...
Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119.
Scope: local
sid: resolved (fixed in 119.0-1)
debian
CVE-2026-4686P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4686 [HIGH] CVE-2026-4686: firefox - Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerab...
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4685P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4685 [HIGH] CVE-2026-4685: firefox - Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerab...
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4707P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4707 [HIGH] CVE-2026-4707: firefox - Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerab...
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2025-14327P3HIGHCVSS 7.5fixed in firefox 146.0-1 (sid)2025
CVE-2025-14327 [HIGH] CVE-2025-14327: firefox - Spoofing issue in the Downloads Panel component. This vulnerability affects Fire...
Spoofing issue in the Downloads Panel component. This vulnerability affects Firefox < 146, Thunderbird < 146, Firefox ESR < 140.7, and Thunderbird < 140.7.
Scope: local
sid: resolved (fixed in 146.0-1)
debian
CVE-2018-12360P3HIGHCVSS 8.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-12360 [HIGH] CVE-2018-12360: firefox - A use-after-free vulnerability can occur when deleting an input element during a...
A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
Scope: local
sid: resolved (fixed in 61.0-1)
debian
CVE-2026-4684P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4684 [HIGH] CVE-2026-4684: firefox - Race condition, use-after-free in the Graphics: WebRender component. This vulner...
Race condition, use-after-free in the Graphics: WebRender component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian