cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 39 of 78
CVE-2023-4055P3HIGHCVSS 7.5fixed in firefox 116.0-1 (sid)2023
CVE-2023-4055 [HIGH] CVE-2023-4055: firefox - When the number of cookies per domain was exceeded in `document.cookie`, the act... When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1. Scope: local sid: resolved (fixed in 116.0
debian
CVE-2024-1546P3HIGHCVSS 7.5fixed in firefox 123.0-1 (sid)2024
CVE-2024-1546 [HIGH] CVE-2024-1546: firefox - When storing and re-accessing data on a networking channel, the length of buffer... When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. Scope: local sid: resolved (fixed in 123.0-1)
debian
CVE-2022-36319P3HIGHCVSS 7.5fixed in firefox 103.0-1 (sid)2022
CVE-2022-36319 [HIGH] CVE-2022-36319: firefox - When combining CSS properties for overflow and transform, the mouse cursor could... When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12. Scope: local sid: resolved (fixed in 103.0-1)
debian
CVE-2023-4583P3HIGHCVSS 7.5fixed in firefox 117.0-1 (sid)2023
CVE-2023-4583 [HIGH] CVE-2023-4583: firefox - When checking if the Browsing Context had been discarded in `HttpBaseChannel`, i... When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2. Scope: local sid: resolved (
debian
CVE-2022-45407P3HIGHCVSS 7.5fixed in firefox 107.0-1 (sid)2022
CVE-2022-45407 [HIGH] CVE-2022-45407: firefox - If an attacker loaded a font using <code>FontFace()</code> on a background worke... If an attacker loaded a font using FontFace() on a background worker, a use-after-free could have occurred, leading to a potentially exploitable crash. This vulnerability affects Firefox < 107. Scope: local sid: resolved (fixed in 107.0-1)
debian
CVE-2026-0889P3HIGHCVSS 7.5fixed in firefox 147.0-1 (sid)2026
CVE-2026-0889 [HIGH] CVE-2026-0889: firefox - Denial-of-service in the DOM: Service Workers component. This vulnerability affe... Denial-of-service in the DOM: Service Workers component. This vulnerability affects Firefox < 147 and Thunderbird < 147. Scope: local sid: resolved (fixed in 147.0-1)
debian
CVE-2024-10458P3HIGHCVSS 7.5fixed in firefox 132.0-1 (sid)2024
CVE-2024-10458 [HIGH] CVE-2024-10458: firefox - A permission leak could have occurred from a trusted site to an untrusted site v... A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132. Scope: local sid: resolved (fixed in 132.0-1)
debian
CVE-2026-4727P3HIGHCVSS 7.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4727 [HIGH] CVE-2026-4727: firefox - Denial-of-service in the Libraries component in NSS. This vulnerability affects ... Denial-of-service in the Libraries component in NSS. This vulnerability affects Firefox < 149 and Thunderbird < 149. Scope: local sid: resolved (fixed in 149.0-1)
debian
CVE-2025-1931P3HIGHCVSS 7.5fixed in firefox 136.0-1 (sid)2025
CVE-2025-1931 [HIGH] CVE-2025-1931: firefox - It was possible to cause a use-after-free in the content process side of a WebTr... It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash. This vulnerability affects Firefox < 136, Firefox ESR < 115.21, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. Scope: local sid: resolved (fixed in 136.0-1)
debian
CVE-2024-11702P3HIGHCVSS 7.5fixed in firefox 134.0-1 (sid)2024
CVE-2024-11702 [HIGH] CVE-2024-11702: firefox - Copying sensitive information from Private Browsing tabs on Android, such as pas... Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133. Scope: local sid: resolved (fixed in 134.0-1)
debian
CVE-2024-5694P3HIGHCVSS 7.5fixed in firefox 127.0-1 (sid)2024
CVE-2024-5694 [HIGH] CVE-2024-5694: firefox - An attacker could have caused a use-after-free in the JavaScript engine to read ... An attacker could have caused a use-after-free in the JavaScript engine to read memory in the JavaScript string section of the heap. This vulnerability affects Firefox < 127. Scope: local sid: resolved (fixed in 127.0-1)
debian
CVE-2022-31748P3CRITICALCVSS 9.8fixed in firefox 101.0-1 (sid)2022
CVE-2022-31748 [CRITICAL] CVE-2022-31748: firefox - Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard,... Mozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 101. Sc
debian
CVE-2022-36320P3CRITICALCVSS 9.8fixed in firefox 103.0-1 (sid)2022
CVE-2022-36320 [CRITICAL] CVE-2022-36320: firefox - Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs pres... Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103. Scope: local sid: resolved (fixed in 103.0-1)
debian
CVE-2016-2815P3HIGHCVSS 8.8fixed in firefox 47.0-1 (sid)2016
CVE-2016-2815 [HIGH] CVE-2016-2815: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be... Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Scope: local sid: resolved (fixed in 47.0-1)
debian
CVE-2016-2835P3HIGHCVSS 8.8fixed in firefox 48.0-1 (sid)2016
CVE-2016-2835 [HIGH] CVE-2016-2835: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be... Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Scope: local sid: resolved (fixed in 48.0-1)
debian
CVE-2016-2797P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2797 [HIGH] CVE-2016-2797: firefox - The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6... The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801. Scope: local sid: re
debian
CVE-2025-10528P3HIGHCVSS 7.3fixed in firefox 143.0-1 (sid)2025
CVE-2025-10528 [HIGH] CVE-2025-10528: firefox - Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canva... Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3. Scope: local sid: resolved (fixed in 143.0-1)
debian
CVE-2025-3029P3HIGHCVSS 7.3fixed in firefox 137.0-1 (sid)2025
CVE-2025-3029 [HIGH] CVE-2025-3029: firefox - A crafted URL containing specific Unicode characters could have hidden the true ... A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9. Scope: local sid: resolved (fixed in 137.0-1)
debian
CVE-2019-9812P3CRITICALCVSS 9.3fixed in firefox 69.0-1 (sid)2019
CVE-2019-9812 [CRITICAL] CVE-2019-9812: firefox - Given a compromised sandboxed content process due to a separate vulnerability, i... Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart without the s
debian
CVE-2006-5747P3HIGHCVSS 7.5fixed in firefox 45.0-1 (sid)2006
CVE-2006-5747 [HIGH] CVE-2006-5747: firefox - Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before ... Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function. Scope: local sid: resolved (fixed in 45.0-1)
debian
Debian Firefox vulnerabilities | cvebase