cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 30 of 78
CVE-2023-29539P3HIGHCVSS 8.8fixed in firefox 112.0-1 (sid)2023
CVE-2023-29539 [HIGH] CVE-2023-29539: firefox - When handling the filename directive in the Content-Disposition header, the file... When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, an
debian
CVE-2018-12393P3HIGHCVSS 7.5fixed in firefox 63.0-1 (sid)2018
CVE-2018-12393 [HIGH] CVE-2018-12393: firefox - A potential vulnerability was found in 32-bit builds where an integer overflow d... A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox < 63, Firefox E
debian
CVE-2023-6213P3HIGHCVSS 8.8fixed in firefox 120.0-1 (sid)2023
CVE-2023-6213 [HIGH] CVE-2023-6213: firefox - Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of... Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120. Scope: local sid: resolved (fixed in 120.0-1)
debian
CVE-2022-31740P3HIGHCVSS 8.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31740 [HIGH] CVE-2022-31740: firefox - On arm64, WASM code could have resulted in incorrect assembly generation leading... On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope: local sid: resolved (fixed in 101.0-1)
debian
CVE-2023-37212P3HIGHCVSS 8.8fixed in firefox 115.0-1 (sid)2023
CVE-2023-37212 [HIGH] CVE-2023-37212: firefox - Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of... Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115. Scope: local sid: resolved (fixed in 115.0-1)
debian
CVE-2017-5396P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5396 [CRITICAL] CVE-2017-5396: firefox - A use-after-free vulnerability in the Media Decoder when working with media file... A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. Scope: local sid: resolved (fixed in 51.0-1)
debian
CVE-2024-6609P3HIGHCVSS 8.8fixed in firefox 128.0-1 (sid)2024
CVE-2024-6609 [HIGH] CVE-2024-6609: firefox - When almost out-of-memory an elliptic curve key which was never allocated could ... When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128. Scope: local sid: resolved (fixed in 128.0-1)
debian
CVE-2016-5276P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5276 [CRITICAL] CVE-2016-5276: firefox - Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalid... Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an aria-owns attribute. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2025-1014P3HIGHCVSS 8.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1014 [HIGH] CVE-2025-1014: firefox - Certificate length was not properly checked when added to a certificate store. I... Certificate length was not properly checked when added to a certificate store. In practice only trusted data was processed. This vulnerability affects Firefox < 135, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135. Scope: local sid: resolved (fixed in 135.0-1)
debian
CVE-2018-18501P3CRITICALCVSS 9.8fixed in firefox 65.0-1 (sid)2018
CVE-2018-18501 [CRITICAL] CVE-2018-18501: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65. Scope: loc
debian
CVE-2018-5155P3CRITICALCVSS 9.8fixed in firefox 60.0-1 (sid)2018
CVE-2018-5155 [CRITICAL] CVE-2018-5155: firefox - A use-after-free vulnerability can occur while adjusting layout during SVG anima... A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8. Scope: local sid: resolved (fixed in 60.0-1)
debian
CVE-2017-7819P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7819 [CRITICAL] CVE-2017-7819: firefox - A use-after-free vulnerability can occur in design mode when image objects are r... A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4. Scope: local sid: resolved (fixed in 56.0-1)
debian
CVE-2018-5089P3CRITICALCVSS 9.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5089 [CRITICAL] CVE-2018-5089: firefox - Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of the... Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. Scope: local sid: resolved (fixed in 58.0-1)
debian
CVE-2017-7826P3CRITICALCVSS 9.8fixed in firefox 57.0-1 (sid)2017
CVE-2017-7826 [CRITICAL] CVE-2017-7826: firefox - Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of the... Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5. Scope: local sid: resolved (fixed in 57.0-1)
debian
CVE-2006-4310P4MEDIUMCVSS 4.3PoCfixed in firefox 45.0-1 (sid)2006
CVE-2006-4310 [MEDIUM] CVE-2006-4310: firefox - Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (cr... Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a username and password via the FTP URI. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2018-12390P3CRITICALCVSS 9.8fixed in firefox 63.0-1 (sid)2018
CVE-2018-12390 [CRITICAL] CVE-2018-12390: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3. Scope: loc
debian
CVE-2018-12405P3CRITICALCVSS 9.8fixed in firefox 64.0-1 (sid)2018
CVE-2018-12405 [CRITICAL] CVE-2018-12405: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64. Scope: loc
debian
CVE-2017-7843P3HIGHCVSS 7.5fixed in firefox 57.0.1-1 (sid)2017
CVE-2017-7843 [HIGH] CVE-2017-7843: firefox - When Private Browsing mode is used, it is possible for a web worker to write per... When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions because it is not cleared when exiting. This vulnerability affects Firefox ESR < 52.5.2 and
debian
CVE-2020-12387P3HIGHCVSS 8.1fixed in firefox 76.0-1 (sid)2020
CVE-2020-12387 [HIGH] CVE-2020-12387: firefox - A race condition when running shutdown code for Web Worker led to a use-after-fr... A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. Scope: local sid: resolved (fixed in 76.0-1)
debian
CVE-2018-12376P3CRITICALCVSS 9.8fixed in firefox 62.0-1 (sid)2018
CVE-2018-12376 [CRITICAL] CVE-2018-12376: firefox - Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bug... Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1. Scope: local sid: resolved (fixed in 62.0-1)
debian
Debian Firefox vulnerabilities | cvebase