cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 31 of 78
CVE-2017-5401P3CRITICALCVSS 9.8fixed in firefox 52.0-1 (sid)2017
CVE-2017-5401 [CRITICAL] CVE-2017-5401: firefox - A crash triggerable by web content in which an "ErrorResult" references unassign... A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. Scope: local sid: resolved (fixed in 52.0-1)
debian
CVE-2021-29986P3HIGHCVSS 8.1fixed in firefox 91.0-1 (sid)2021
CVE-2021-29986 [HIGH] CVE-2021-29986: firefox - A suspected race condition when calling getaddrinfo led to memory corruption and... A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91. Scope: local sid: resolved (fixed in 91.0-1)
debian
CVE-2017-5440P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5440 [CRITICAL] CVE-2017-5440: firefox - A use-after-free vulnerability during XSLT processing due to a failure to propag... A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. Scope: local
debian
CVE-2018-5187P3CRITICALCVSS 9.8fixed in firefox 61.0-1 (sid)2018
CVE-2018-5187 [CRITICAL] CVE-2018-5187: firefox - Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs ... Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61. Scope: local sid: resolved (fixed in 61.0-1)
debian
CVE-2017-7751P3CRITICALCVSS 9.8fixed in firefox 54.0-1 (sid)2017
CVE-2017-7751 [CRITICAL] CVE-2017-7751: firefox - A use-after-free vulnerability with content viewer listeners that results in a p... A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. Scope: local sid: resolved (fixed in 54.0-1)
debian
CVE-2017-7802P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7802 [CRITICAL] CVE-2017-7802: firefox - A use-after-free vulnerability can occur when manipulating the DOM during the re... A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements are accessed. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. Scope: local sid: r
debian
CVE-2017-7801P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7801 [CRITICAL] CVE-2017-7801: firefox - A use-after-free vulnerability can occur while re-computing layout for a "marque... A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. Scope: local sid: resolved (fixed in 55.0-1)
debian
CVE-2025-1943P3HIGHCVSS 8.2fixed in firefox 136.0-1 (sid)2025
CVE-2025-1943 [HIGH] CVE-2025-1943: firefox - Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bug... Memory safety bugs present in Firefox 135 and Thunderbird 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 136 and Thunderbird < 136. Scope: local sid: resolved (fixed in 136.0-1)
debian
CVE-2024-7525P3HIGHCVSS 8.1fixed in firefox 129.0-1 (sid)2024
CVE-2024-7525 [HIGH] CVE-2024-7525: firefox - It was possible for a web extension with minimal permissions to create a `Stream... It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14. Scope: local sid: resolved (fixed in 129.0-1)
debian
CVE-2016-2804P3HIGHCVSS 8.8fixed in firefox 46.0-1 (sid)2016
CVE-2016-2804 [HIGH] CVE-2016-2804: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be... Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Scope: local sid: resolved (fixed in 46.0-1)
debian
CVE-2024-1557P3HIGHCVSS 8.1fixed in firefox 123.0-1 (sid)2024
CVE-2024-1557 [HIGH] CVE-2024-1557: firefox - Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of... Memory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123. Scope: local sid: resolved (fixed in 123.0-1)
debian
CVE-2024-3865P3HIGHCVSS 8.1fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3865 [HIGH] CVE-2024-3865: firefox - Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of... Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
CVE-2024-11700P3HIGHCVSS 8.1fixed in firefox 134.0-1 (sid)2024
CVE-2024-11700 [HIGH] CVE-2024-11700: firefox - Malicious websites may have been able to perform user intent confirmation throug... Malicious websites may have been able to perform user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133. Scope: local sid: resolved (fixed in 134.0-1)
debian
CVE-2025-1932P3HIGHCVSS 8.1fixed in firefox 136.0-1 (sid)2025
CVE-2025-1932 [HIGH] CVE-2025-1932: firefox - An inconsistent comparator in xslt/txNodeSorter could have resulted in potential... An inconsistent comparator in xslt/txNodeSorter could have resulted in potentially exploitable out-of-bounds access. Only affected version 122 and later. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. Scope: local sid: resolved (fixed in 136.0-1)
debian
CVE-2018-5137P3HIGHCVSS 7.5fixed in firefox 59.0-1 (sid)2018
CVE-2018-5137 [HIGH] CVE-2018-5137: firefox - A legacy extension's non-contentaccessible, defined resources can be loaded by a... A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect WebExtensions. This vulnerability affects Firefox < 59. Scope: local sid: resolved (fixed in 59.0-1)
debian
CVE-2020-6814P3CRITICALCVSS 9.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6814 [CRITICAL] CVE-2020-6814: firefox - Mozilla developers reported memory safety bugs present in Firefox and Thunderbir... Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6. Scope: local sid
debian
CVE-2017-5377P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5377 [CRITICAL] CVE-2017-5377: firefox - A memory corruption vulnerability in Skia that can occur when using transforms t... A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 51. Scope: local sid: resolved (fixed in 51.0-1)
debian
CVE-2017-7753P3CRITICALCVSS 9.1fixed in firefox 55.0-1 (sid)2017
CVE-2017-7753 [CRITICAL] CVE-2017-7753: firefox - An out-of-bounds read occurs when applying style rules to pseudo-elements, such ... An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. Scope: local sid: resolved (fixed in 55.0-1)
debian
CVE-2026-4699P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4699 [HIGH] CVE-2026-4699: firefox - Incorrect boundary conditions in the Layout: Text and Fonts component. This vuln... Incorrect boundary conditions in the Layout: Text and Fonts component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4693P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4693 [HIGH] CVE-2026-4693: firefox - Incorrect boundary conditions in the Audio/Video: Playback component. This vulne... Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. Scope: local sid: resolved (fixed in 149.0-1)
debian
Debian Firefox vulnerabilities | cvebase