Debian Firefox vulnerabilities
1,810 known vulnerabilities affecting debian/firefox.
Total CVEs
1,810
CISA KEV
11
actively exploited
Public exploits
35
Exploited in wild
15
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW302
Vulnerabilities
Page 43 of 91
CVE-2021-29988HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29988 [HIGH] CVE-2021-29988: firefox - Firefox incorrectly treated an inline list-item element as a block element, resu...
Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Scope: local
sid: resolved (fixed in 91.0-1)
debian
CVE-2021-29977HIGHCVSS 8.8fixed in firefox 90.0-1 (sid)2021
CVE-2021-29977 [HIGH] CVE-2021-29977: firefox - Mozilla developers reported memory safety bugs present in Firefox 89. Some of th...
Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 90.
Scope: local
sid: resolved (fixed in 90.0-1)
debian
CVE-2021-23979HIGHCVSS 8.8fixed in firefox 86.0-1 (sid)2021
CVE-2021-23979 [HIGH] CVE-2021-23979: firefox - Mozilla developers reported memory safety bugs present in Firefox 85. Some of th...
Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86.
Scope: local
sid: resolved (fixed in 86.0-1)
debian
CVE-2021-29967HIGHCVSS 8.8fixed in firefox 89.0-1 (sid)2021
CVE-2021-29967 [HIGH] CVE-2021-29967: firefox - Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
Scope: local
sid: resolved (fix
debian
CVE-2021-24002HIGHCVSS 8.8fixed in firefox 88.0-1 (sid)2021
CVE-2021-24002 [HIGH] CVE-2021-24002: firefox - When a user clicked on an FTP URL containing encoded newline characters (%0A and...
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2021-29984HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29984 [HIGH] CVE-2021-29984: firefox - Instruction reordering resulted in a sequence of instructions that would cause a...
Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Scope: local
sid: resolved (fixed in 91.0-1)
debian
CVE-2021-29990HIGHCVSS 8.8fixed in firefox 91.0-1 (sid)2021
CVE-2021-29990 [HIGH] CVE-2021-29990: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 91.
Scope: local
sid: resolved (fixed in 91.0-1)
debian
CVE-2021-29986HIGHCVSS 8.1fixed in firefox 91.0-1 (sid)2021
CVE-2021-29986 [HIGH] CVE-2021-29986: firefox - A suspected race condition when calling getaddrinfo led to memory corruption and...
A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affected Linux operating systems. Other operating systems are unaffected.* This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
Scope: local
sid: resolved (fixed in 91.0-1)
debian
CVE-2021-38501HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-38501 [HIGH] CVE-2021-38501: firefox - Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
Scope: local
sid: resolved (fixed
debian
CVE-2021-29991HIGHCVSS 8.1fixed in firefox 91.0.1-1 (sid)2021
CVE-2021-29991 [HIGH] CVE-2021-29991: firefox - Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as t...
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 and Thunderbird < 91.0.1.
Scope: local
sid: resolved (fixed in 91.0.1-1)
debian
CVE-2021-38499HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-38499 [HIGH] CVE-2021-38499: firefox - Mozilla developers reported memory safety bugs present in Firefox 92. Some of th...
Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93.
Scope: local
sid: resolved (fixed in 93.0-1)
debian
CVE-2021-38496HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-38496 [HIGH] CVE-2021-38496: firefox - During operations on MessageTasks, a task may have been removed while it was sti...
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
Scope: local
sid: resolved (fixed in 93.0-1)
debian
CVE-2021-38493HIGHCVSS 8.8fixed in firefox 92.0-1 (sid)2021
CVE-2021-38493 [HIGH] CVE-2021-38493: firefox - Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.
Scope: local
sid: resolved (fix
debian
CVE-2021-23994HIGHCVSS 8.8fixed in firefox 88.0-1 (sid)2021
CVE-2021-23994 [HIGH] CVE-2021-23994: firefox - A WebGL framebuffer was not initialized early enough, resulting in memory corrup...
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2021-23981HIGHCVSS 8.1fixed in firefox 87.0-1 (sid)2021
CVE-2021-23981 [HIGH] CVE-2021-23981: firefox - A texture upload of a Pixel Buffer Object could have confused the WebGL code to ...
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
Scope: local
sid: resolved (fixed in 87.0-1)
debian
CVE-2021-23954HIGHCVSS 8.8fixed in firefox 85.0-1 (sid)2021
CVE-2021-23954 [HIGH] CVE-2021-23954: firefox - Using the new logical assignment operators in a JavaScript switch statement coul...
Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
Scope: local
sid: resolved (fixed in 85.0-1)
debian
CVE-2021-23972HIGHCVSS 8.8fixed in firefox 86.0-1 (sid)2021
CVE-2021-23972 [HIGH] CVE-2021-23972: firefox - One phishing tactic on the web is to provide a link with HTTP Auth. For example ...
One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://[email protected]'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.
Scope: local
debian
CVE-2021-43534HIGHCVSS 8.8fixed in firefox 94.0-1 (sid)2021
CVE-2021-43534 [HIGH] CVE-2021-43534: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
Scope: local
debian
CVE-2021-23960HIGHCVSS 8.8fixed in firefox 85.0-1 (sid)2021
CVE-2021-23960 [HIGH] CVE-2021-23960: firefox - Performing garbage collection on re-declared JavaScript variables resulted in a ...
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
Scope: local
sid: resolved (fixed in 85.0-1)
debian
CVE-2021-38500HIGHCVSS 8.8fixed in firefox 93.0-1 (sid)2021
CVE-2021-38500 [HIGH] CVE-2021-38500: firefox - Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefo
debian