Debian Firefox vulnerabilities

1,810 known vulnerabilities affecting debian/firefox.

Total CVEs
1,810
CISA KEV
11
actively exploited
Public exploits
35
Exploited in wild
15
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW302

Vulnerabilities

Page 35 of 91
CVE-2022-36320CRITICALCVSS 9.8fixed in firefox 103.0-1 (sid)2022
CVE-2022-36320 [CRITICAL] CVE-2022-36320: firefox - Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs pres... Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103. Scope: local sid: resolved (fixed in 103.0-1)
debian
CVE-2022-34470CRITICALCVSS 9.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34470 [CRITICAL] CVE-2022-34470: firefox - Session history navigations may have led to a use-after-free and potentially exp... Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11. Scope: local sid: resolved (fixed in 102.0-1)
debian
CVE-2022-22759CRITICALCVSS 9.6fixed in firefox 97.0-1 (sid)2022
CVE-2022-22759 [CRITICAL] CVE-2022-22759: firefox - If a document created a sandboxed iframe without <code>allow-scripts</code>, and... If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6. Scope: local sid: resolved (fixed in 97.0-1)
debian
CVE-2022-31737CRITICALCVSS 9.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31737 [CRITICAL] CVE-2022-31737: firefox - A malicious webpage could have caused an out-of-bounds write in WebGL, leading t... A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10. Scope: local sid: resolved (fixed in 101.0-1)
debian
CVE-2022-34485CRITICALCVSS 9.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34485 [CRITICAL] CVE-2022-34485: firefox - Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported po... Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 102. Scope: local sid: resolved (fixed in
debian
CVE-2022-29917CRITICALCVSS 9.8fixed in firefox 100.0-1 (sid)2022
CVE-2022-29917 [CRITICAL] CVE-2022-29917: firefox - Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla... Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird <
debian
CVE-2022-22738HIGHCVSS 8.8fixed in firefox 96.0-1 (sid)2022
CVE-2022-22738 [HIGH] CVE-2022-22738: firefox - Applying a CSS filter effect could have accessed out of bounds memory. This coul... Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2022-45412HIGHCVSS 8.8fixed in firefox 107.0-1 (sid)2022
CVE-2022-45412 [HIGH] CVE-2022-45412: firefox - When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error m... When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. *This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and F
debian
CVE-2022-46884HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-46884 [HIGH] CVE-2022-46884: firefox - A potential use-after-free vulnerability existed in SVG Images if the Refresh Dr... A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune time. This could have lead to memory corruption or a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after discovering it was inadvertently left out of the original advisory. The fix was included in the original r
debian
CVE-2022-0843HIGHCVSS 8.8fixed in firefox 98.0-1 (sid)2022
CVE-2022-0843 [HIGH] CVE-2022-0843: firefox - Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported ... Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 98. Scope: local sid: resolved (fixed in 98.0-1)
debian
CVE-2022-28288HIGHCVSS 8.8fixed in firefox 99.0-1 (sid)2022
CVE-2022-28288 [HIGH] CVE-2022-28288: firefox - Mozilla developers and community members Randell Jesup, Sebastian Hengst, and th... Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 98. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 99. Scope: local si
debian
CVE-2022-34483HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34483 [HIGH] CVE-2022-34483: firefox - An attacker who could have convinced a user to drag and drop an image to a files... An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34482. This vulnerability affects Firefox < 102. Scope: local si
debian
CVE-2022-46871HIGHCVSS 8.8fixed in firefox 108.0-1 (sid)2022
CVE-2022-46871 [HIGH] CVE-2022-46871: firefox - An out of date library (libusrsctp) contained vulnerabilities that could potenti... An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108. Scope: local sid: resolved (fixed in 108.0-1)
debian
CVE-2022-22740HIGHCVSS 8.8fixed in firefox 96.0-1 (sid)2022
CVE-2022-22740 [HIGH] CVE-2022-22740: firefox - Certain network request objects were freed too early when releasing a network re... Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2022-24713HIGHCVSS 7.5fixed in firefox 99.0-1 (sid)2022
CVE-2022-24713 [HIGH] CVE-2022-24713: firefox - regex is an implementation of regular expressions for the Rust language. The reg... regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of t
debian
CVE-2022-34482HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34482 [HIGH] CVE-2022-34482: firefox - An attacker who could have convinced a user to drag and drop an image to a files... An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34483. This vulnerability affects Firefox < 102. Scope: local si
debian
CVE-2022-42928HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-42928 [HIGH] CVE-2022-42928: firefox - Certain types of allocations were missing annotations that, if the Garbage Colle... Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4. Scope: local sid: resolved (fixed in 106.0-1)
debian
CVE-2022-42927HIGHCVSS 8.1fixed in firefox 106.0-1 (sid)2022
CVE-2022-42927 [HIGH] CVE-2022-42927: firefox - A same-origin policy violation could have allowed the theft of cross-origin URL ... A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4. Scope: local sid: resolved (fixed in 106.0-1)
debian
CVE-2022-2505HIGHCVSS 8.8fixed in firefox 103.0-1 (sid)2022
CVE-2022-2505 [HIGH] CVE-2022-2505: firefox - Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs pres... Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1. Scope: local sid: resolv
debian
CVE-2022-26381HIGHCVSS 8.8fixed in firefox 98.0-1 (sid)2022
CVE-2022-26381 [HIGH] CVE-2022-26381: firefox - An attacker could have caused a use-after-free by forcing a text reflow in an SV... An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7. Scope: local sid: resolved (fixed in 98.0-1)
debian