cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 35 of 78
CVE-2025-9180P3HIGHCVSS 8.1fixed in firefox 142.0-1 (sid)2025
CVE-2025-9180 [HIGH] CVE-2025-9180: firefox - Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerabilit... Same-origin policy bypass in the Graphics: Canvas2D component. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. Scope: local sid: resolved (fixed in 142.0-1)
debian
CVE-2026-0878P3HIGHCVSS 8.0fixed in firefox 147.0-1 (sid)2026
CVE-2026-0878 [HIGH] CVE-2026-0878: firefox - Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL... Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7. Scope: local sid: resolved (fixed in 147.0-1)
debian
CVE-2017-5413P3CRITICALCVSS 9.8fixed in firefox 52.0-1 (sid)2017
CVE-2017-5413 [CRITICAL] CVE-2017-5413: firefox - A segmentation fault can occur during some bidirectional layout operations. This... A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52. Scope: local sid: resolved (fixed in 52.0-1)
debian
CVE-2020-6809P3HIGHCVSS 7.5fixed in firefox 74.0-1 (sid)2020
CVE-2020-6809 [HIGH] CVE-2020-6809: firefox - When a Web Extension had the all-urls permission and made a fetch request with a... When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74. Scope: local sid: resolved (fixed in 74.0-1)
debian
CVE-2019-9802P3HIGHCVSS 7.5fixed in firefox 66.0-1 (sid)2019
CVE-2019-9802 [HIGH] CVE-2019-9802: firefox - If a Sandbox content process is compromised, it can initiate an FTP download whi... If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an attacker, bypassing sandbox protections and allow for a potential memory read of adjacent data from the privileged Chrom
debian
CVE-2017-7758P3CRITICALCVSS 9.1fixed in firefox 54.0-1 (sid)2017
CVE-2017-7758 [CRITICAL] CVE-2017-7758: firefox - An out-of-bounds read vulnerability with the Opus encoder when the number of cha... An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2. Scope: local sid: resolved (fixed in 54.0-1)
debian
CVE-2024-3857P3HIGHCVSS 7.8fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3857 [HIGH] CVE-2024-3857: firefox - The JIT created incorrect code for arguments in certain cases. This led to poten... The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
CVE-2019-9805P3CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9805 [CRITICAL] CVE-2019-9805: firefox - A latent vulnerability exists in the Prio library where data may be read from un... A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66. Scope: local sid: resolved (fixed in 66.0-1)
debian
CVE-2026-4694P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4694 [HIGH] CVE-2026-4694: firefox - Incorrect boundary conditions, integer overflow in the Graphics component. This ... Incorrect boundary conditions, integer overflow in the Graphics component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2006-1739P3MEDIUMCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1739 [CRITICAL] CVE-2006-1739: firefox - The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 ... The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow. Scope: l
debian
CVE-2021-29952P3HIGHCVSS 7.5fixed in firefox 88.0.1-1 (sid)2021
CVE-2021-29952 [HIGH] CVE-2021-29952: firefox - When Web Render components were destructed, a race condition could have caused u... When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for Android < 88.1.3. Scope: local sid: resolved (fixed in 88.0.1-1)
debian
CVE-2026-4697P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4697 [HIGH] CVE-2026-4697: firefox - Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vul... Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4695P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4695 [HIGH] CVE-2026-4695: firefox - Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vul... Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2024-1552P3HIGHCVSS 7.5fixed in firefox 123.0-1 (sid)2024
CVE-2024-1552 [HIGH] CVE-2024-1552: firefox - Incorrect code generation could have led to unexpected numeric conversions and p... Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. Scope: local sid: resolved (fixed in 123.0-1)
debian
CVE-2023-4051P3HIGHCVSS 7.5fixed in firefox 116.0-1 (sid)2023
CVE-2023-4051 [HIGH] CVE-2023-4051: firefox - A website could have obscured the full screen notification by using the file ope... A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2. Scope: local sid: resolved (fixed in 116.0-1)
debian
CVE-2022-26387P3HIGHCVSS 7.5fixed in firefox 98.0-1 (sid)2022
CVE-2022-26387 [HIGH] CVE-2022-26387: firefox - When installing an add-on, Firefox verified the signature before prompting the u... When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7. Scope: local sid: resolved (fixed in 98.0-1)
debian
CVE-2022-22741P3HIGHCVSS 7.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22741 [HIGH] CVE-2022-22741: firefox - When resizing a popup while requesting fullscreen access, the popup would have b... When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2024-8383P3HIGHCVSS 7.5fixed in firefox 130.0-1 (sid)2024
CVE-2024-8383 [HIGH] CVE-2024-8383: firefox - Firefox normally asks for confirmation before asking the operating system to fin... Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could r
debian
CVE-2026-4726P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4726 [HIGH] CVE-2026-4726: firefox - Denial-of-service in the XML component. This vulnerability affects Firefox < 149... Denial-of-service in the XML component. This vulnerability affects Firefox < 149 and Thunderbird < 149. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2023-34417P3CRITICALCVSS 9.8fixed in firefox 114.0-1 (sid)2023
CVE-2023-34417 [CRITICAL] CVE-2023-34417: firefox - Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of... Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114. Scope: local sid: resolved (fixed in 114.0-1)
debian
Debian Firefox vulnerabilities | cvebase