cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 34 of 78
CVE-2022-46879P3HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46879 [HIGH] CVE-2022-46879: firefox - Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randel... Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 107. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108
debian
CVE-2022-0843P3HIGHCVSS 8.8fixed in firefox 98.0-1 (sid)2022
CVE-2022-0843 [HIGH] CVE-2022-0843: firefox - Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported ... Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 98. Scope: local sid: resolved (fixed in 98.0-1)
debian
CVE-2023-28177P3HIGHCVSS 8.8fixed in firefox 111.0-1 (sid)2023
CVE-2023-28177 [HIGH] CVE-2023-28177: firefox - Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of... Memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111. Scope: local sid: resolved (fixed in 111.0-1)
debian
CVE-2023-29543P3HIGHCVSS 8.8fixed in firefox 112.0-1 (sid)2023
CVE-2023-29543 [HIGH] CVE-2023-29543: firefox - An attacker could have caused memory corruption and a potentially exploitable us... An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. Scope: local sid: resolved (fixed in 112.0-1)
debian
CVE-2023-23606P3HIGHCVSS 8.8fixed in firefox 109.0-1 (sid)2023
CVE-2023-23606 [HIGH] CVE-2023-23606: firefox - Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs pres... Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109. Scope: local sid: resolved (fixed in 109.0-1)
debian
CVE-2022-0511P3HIGHCVSS 8.8fixed in firefox 97.0-1 (sid)2022
CVE-2022-0511 [HIGH] CVE-2022-0511: firefox - Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Rand... Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnera
debian
CVE-2016-5277P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5277 [CRITICAL] CVE-2016-5277: firefox - Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Fi... Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation. S
debian
CVE-2022-46884P3HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-46884 [HIGH] CVE-2022-46884: firefox - A potential use-after-free vulnerability existed in SVG Images if the Refresh Dr... A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune time. This could have lead to memory corruption or a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after discovering it was inadvertently left out of the original advisory. The fix was included in the original r
debian
CVE-2017-5373P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5373 [CRITICAL] CVE-2017-5373: firefox - Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of t... Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. Scope: local sid: resolved (fixed in 51.0-1)
debian
CVE-2016-5290P3CRITICALCVSS 9.8fixed in firefox 50.0-1 (sid)2016
CVE-2016-5290 [CRITICAL] CVE-2016-5290: firefox - Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of the... Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50. Scope: local sid: resolved (fixed in 50.0-1)
debian
CVE-2017-7810P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7810 [CRITICAL] CVE-2017-7810: firefox - Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of the... Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4. Scope: local sid: resolved (fixed in 56.0-1)
debian
CVE-2017-5454P3HIGHCVSS 7.5fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5454 [HIGH] CVE-2017-5454: firefox - A mechanism to bypass file system access protections in the sandbox to use the f... A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53. Scope: local sid: resolved (fixed i
debian
CVE-2024-1555P3HIGHCVSS 8.3fixed in firefox 123.0-1 (sid)2024
CVE-2024-1555 [HIGH] CVE-2024-1555: firefox - When opening a website using the `firefox://` protocol handler, SameSite cookies... When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123. Scope: local sid: resolved (fixed in 123.0-1)
debian
CVE-2017-7779P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7779 [CRITICAL] CVE-2017-7779: firefox - Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbir... Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. Scope: local sid: resolved (fixed in
debian
CVE-2017-7809P3CRITICALCVSS 9.8fixed in firefox 55.0-1 (sid)2017
CVE-2017-7809 [CRITICAL] CVE-2017-7809: firefox - A use-after-free vulnerability can occur when an editor DOM node is deleted prem... A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. Scope: local sid: resolved (fixed in 55.0-1)
debian
CVE-2017-7793P3CRITICALCVSS 9.8fixed in firefox 56.0-1 (sid)2017
CVE-2017-7793 [CRITICAL] CVE-2017-7793: firefox - A use-after-free vulnerability can occur in the Fetch API when the worker or the... A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4. Scope: local sid: resolved (fixed in 56.0-1)
debian
CVE-2018-5112P3HIGHCVSS 7.5fixed in firefox 58.0-1 (sid)2018
CVE-2018-5112 [HIGH] CVE-2018-5112: firefox - Development Tools panels of an extension are required to load URLs for the panel... Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnerability affects
debian
CVE-2016-2806P3HIGHCVSS 8.8fixed in firefox 46.0-1 (sid)2016
CVE-2016-2806 [HIGH] CVE-2016-2806: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be... Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Scope: local sid: resolved (fixed in 46.0-1)
debian
CVE-2025-8030P3HIGHCVSS 8.1fixed in firefox 141.0-1 (sid)2025
CVE-2025-8030 [HIGH] CVE-2025-8030: firefox - Insufficient escaping in the “Copy as cURL” feature could potentially be used to... Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. Scope: local sid: resolved (fixed in 141.0-1)
debian
CVE-2017-5386P3HIGHCVSS 7.3fixed in firefox 51.0-1 (sid)2017
CVE-2017-5386 [HIGH] CVE-2017-5386: firefox - WebExtension scripts can use the "data:" protocol to affect pages loaded by othe... WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51. Scope: local sid: resolved (fixed in 51.0-1)
debian
Debian Firefox vulnerabilities | cvebase