cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 29 of 78
CVE-2024-2615P3CRITICALCVSS 9.8fixed in firefox 124.0-1 (sid)2024
CVE-2024-2615 [CRITICAL] CVE-2024-2615: firefox - Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of... Memory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124. Scope: local sid: resolved (fixed in 124.0-1)
debian
CVE-2016-1974P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1974 [HIGH] CVE-2016-1974: firefox - The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and... The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2024-4778P3CRITICALCVSS 9.8fixed in firefox 126.0-1 (sid)2024
CVE-2024-4778 [CRITICAL] CVE-2024-4778: firefox - Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of... Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126. Scope: local sid: resolved (fixed in 126.0-1)
debian
CVE-2016-1966P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1966 [HIGH] CVE-2016-1966: firefox - The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp ... The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference and memory corruption) via a crafted NPAPI plugin. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2020-12417P3HIGHCVSS 8.8fixed in firefox 78.0-1 (sid)2020
CVE-2020-12417 [HIGH] CVE-2020-12417: firefox - Due to confusion about ValueTags on JavaScript Objects, an object may pass throu... Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0. Scope: local sid: resolved (fixed in 78.0-1)
debian
CVE-2020-6806P3HIGHCVSS 8.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6806 [HIGH] CVE-2020-6806: firefox - By carefully crafting promise resolutions, it was possible to cause an out-of-bo... By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6. Scope: local sid: resolved (fixed in 74.0
debian
CVE-2025-14325P3HIGHCVSS 7.3fixed in firefox 146.0-1 (sid)2025
CVE-2025-14325 [HIGH] CVE-2025-14325: firefox - JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability a... JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6. Scope: local sid: resolved (fixed in 146.0-1)
debian
CVE-2019-11752P3HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11752 [HIGH] CVE-2019-11752: firefox - It is possible to delete an IndexedDB key value and subsequently try to extract ... It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1. Scope: local sid: resolved (fixed in 69.0-1)
debian
CVE-2017-7752P3HIGHCVSS 8.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7752 [HIGH] CVE-2017-7752: firefox - A use-after-free vulnerability during specific user interactions with the input ... A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. Scope: local sid: resolved (fixe
debian
CVE-2019-17012P3HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17012 [HIGH] CVE-2019-17012: firefox - Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox... Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed
debian
CVE-2020-12422P3HIGHCVSS 8.8fixed in firefox 78.0-1 (sid)2020
CVE-2020-12422 [HIGH] CVE-2020-12422: firefox - In non-standard configurations, a JPEG image created by JavaScript could have ca... In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78. Scope: local sid: resolved (fixed in 78.0-1)
debian
CVE-2020-12420P3HIGHCVSS 8.8fixed in firefox 78.0-1 (sid)2020
CVE-2020-12420 [HIGH] CVE-2020-12420: firefox - When trying to connect to a STUN server, a race condition could have caused a us... When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0. Scope: local sid: resolved (fixed in 78.0-1)
debian
CVE-2019-11746P3HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11746 [HIGH] CVE-2019-11746: firefox - A use-after-free vulnerability can occur while manipulating video elements if th... A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1. Scope: local sid: resolved (fixed in 69.0-1)
debian
CVE-2020-12410P3HIGHCVSS 8.8fixed in firefox 77.0-1 (sid)2020
CVE-2020-12410 [HIGH] CVE-2020-12410: firefox - Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox... Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. Scope: local sid: resolved (fixe
debian
CVE-2019-11764P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11764 [HIGH] CVE-2019-11764: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: r
debian
CVE-2021-29988P3HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29988 [HIGH] CVE-2021-29988: firefox - Firefox incorrectly treated an inline list-item element as a block element, resu... Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91. Scope: local sid: resolved (fixed in 91.0-1)
debian
CVE-2019-11757P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11757 [HIGH] CVE-2019-11757: firefox - When following the value's prototype chain, it was possible to retain a referenc... When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2018-6156P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2018
CVE-2018-6156 [HIGH] CVE-2018-6156: firefox - Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.... Incorect derivation of a packet length in WebRTC in Google Chrome prior to 68.0.3440.75 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2016-5257P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5257 [CRITICAL] CVE-2016-5257: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be... Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2023-25732P3HIGHCVSS 8.8fixed in firefox 110.0-1 (sid)2023
CVE-2023-25732 [HIGH] CVE-2023-25732: firefox - When encoding data from an <code>inputStream</code> in <code>xpcom</code> the si... When encoding data from an inputStream in xpcom the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8. Scope: local sid: resolved (fixed in 110.0-1)
debian
Debian Firefox vulnerabilities | cvebase