cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 37 of 78
CVE-2020-12426P3HIGHCVSS 8.8fixed in firefox 78.0-1 (sid)2020
CVE-2020-12426 [HIGH] CVE-2020-12426: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 78. Scope: local sid: resolved (fixed in 78.0-1)
debian
CVE-2020-6796P3HIGHCVSS 8.8fixed in firefox 73.0-1 (sid)2020
CVE-2020-6796 [HIGH] CVE-2020-6796: firefox - A content process could have modified shared memory relating to crash reporting ... A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 73 and Firefox < ESR68.5. Scope: local sid: resolved (fixed in 73.0-1)
debian
CVE-2019-11756P3HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-11756 [HIGH] CVE-2019-11756: firefox - Improper refcounting of soft token session objects could cause a use-after-free ... Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2016-5283P3HIGHCVSS 8.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5283 [HIGH] CVE-2016-5283: firefox - Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Po... Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2018-18503P3HIGHCVSS 8.8fixed in firefox 65.0-1 (sid)2018
CVE-2018-18503 [HIGH] CVE-2018-18503: firefox - When JavaScript is used to create and manipulate an audio buffer, a potentially ... When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some situations. This vulnerability affects Firefox < 65. Scope: local sid: resolved (fixed in 65.0-1)
debian
CVE-2019-11760P3HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11760 [HIGH] CVE-2019-11760: firefox - A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling... A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2020-12416P3HIGHCVSS 8.8fixed in firefox 78.0-1 (sid)2020
CVE-2020-12416 [HIGH] CVE-2020-12416: firefox - A VideoStreamEncoder may have been freed in a race condition with VideoBroadcast... A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 78. Scope: local sid: resolved (fixed in 78.0-1)
debian
CVE-2017-5412P3HIGHCVSS 7.5fixed in firefox 52.0-1 (sid)2017
CVE-2017-5412 [HIGH] CVE-2017-5412: firefox - A buffer overflow read during SVG filter color value operations, resulting in da... A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52. Scope: local sid: resolved (fixed in 52.0-1)
debian
CVE-2021-29946P3HIGHCVSS 8.8fixed in firefox 88.0-1 (sid)2021
CVE-2021-29946 [HIGH] CVE-2021-29946: firefox - Ports that were written as an integer overflow above the bounds of a 16-bit inte... Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88. Scope: local sid: resolved (fixed in 88.0-1)
debian
CVE-2020-26969P3HIGHCVSS 8.8fixed in firefox 83.0-1 (sid)2020
CVE-2020-26969 [HIGH] CVE-2020-26969: firefox - Mozilla developers reported memory safety bugs present in Firefox 82. Some of th... Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83. Scope: local sid: resolved (fixed in 83.0-1)
debian
CVE-2021-23954P3HIGHCVSS 8.8fixed in firefox 85.0-1 (sid)2021
CVE-2021-23954 [HIGH] CVE-2021-23954: firefox - Using the new logical assignment operators in a JavaScript switch statement coul... Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7. Scope: local sid: resolved (fixed in 85.0-1)
debian
CVE-2019-11735P3HIGHCVSS 8.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11735 [HIGH] CVE-2019-11735: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1. Scope: local sid: resolved (fixed in
debian
CVE-2020-26952P3HIGHCVSS 8.8fixed in firefox 83.0-1 (sid)2020
CVE-2020-26952 [HIGH] CVE-2020-26952: firefox - Incorrect bookkeeping of functions inlined during JIT compilation could have led... Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially exploitable crash when handling out-of-memory errors. This vulnerability affects Firefox < 83. Scope: local sid: resolved (fixed in 83.0-1)
debian
CVE-2021-38499P3HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-38499 [HIGH] CVE-2021-38499: firefox - Mozilla developers reported memory safety bugs present in Firefox 92. Some of th... Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93. Scope: local sid: resolved (fixed in 93.0-1)
debian
CVE-2021-38494P3HIGHCVSS 8.8fixed in firefox 92.0-1 (sid)2021
CVE-2021-38494 [HIGH] CVE-2021-38494: firefox - Mozilla developers reported memory safety bugs present in Firefox 91. Some of th... Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 92. Scope: local sid: resolved (fixed in 92.0-1)
debian
CVE-2022-34480P3HIGHCVSS 8.8fixed in firefox 102.0-1 (sid)2022
CVE-2022-34480 [HIGH] CVE-2022-34480: firefox - Within the <code>lg_init()</code> function, if several allocations succeed but t... Within the lg_init() function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102. Scope: local sid: resolved (fixed in 102.0-1)
debian
CVE-2022-28288P3HIGHCVSS 8.8fixed in firefox 99.0-1 (sid)2022
CVE-2022-28288 [HIGH] CVE-2022-28288: firefox - Mozilla developers and community members Randell Jesup, Sebastian Hengst, and th... Mozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 98. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 99. Scope: local si
debian
CVE-2022-29918P3HIGHCVSS 8.8fixed in firefox 100.0-1 (sid)2022
CVE-2022-29918 [HIGH] CVE-2022-29918: firefox - Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team r... Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 100. Scope: local sid: resolved (fixed in 1
debian
CVE-2022-22752P3HIGHCVSS 8.8fixed in firefox 96.0-1 (sid)2022
CVE-2022-22752 [HIGH] CVE-2022-22752: firefox - Mozilla developers Christian Holler and Jason Kratzer reported memory safety bug... Mozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 96. Scope: local sid: resolved (fixed in 96.0-1)
debian
CVE-2022-46885P3HIGHCVSS 8.8fixed in firefox 106.0-1 (sid)2022
CVE-2022-46885 [HIGH] CVE-2022-46885: firefox - Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team rep... Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106. Scope: local sid: resolved (fixed in 10
debian
Debian Firefox vulnerabilities | cvebase