Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 43 of 78
CVE-2024-4773P3HIGHCVSS 7.5fixed in firefox 126.0-1 (sid)2024
CVE-2024-4773 [HIGH] CVE-2024-4773: firefox - When a network error occurred during page load, the prior content could have rem...
When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.
Scope: local
sid: resolved (fixed in 126.0-1)
debian
CVE-2024-2613P3HIGHCVSS 7.5fixed in firefox 124.0-1 (sid)2024
CVE-2024-2613 [HIGH] CVE-2024-2613: firefox - Data was not properly sanitized when decoding a QUIC ACK frame; this could have ...
Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.
Scope: local
sid: resolved (fixed in 124.0-1)
debian
CVE-2024-9399P3HIGHCVSS 7.5fixed in firefox 131.0-1 (sid)2024
CVE-2024-9399 [HIGH] CVE-2024-9399: firefox - A website configured to initiate a specially crafted WebTransport session could ...
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
Scope: local
sid: resolved (fixed in 131.0-1)
debian
CVE-2026-2801P3HIGHCVSS 7.5fixed in firefox 148.0-1 (sid)2026
CVE-2026-2801 [HIGH] CVE-2026-2801: firefox - Incorrect boundary conditions in the JavaScript: WebAssembly component. This vul...
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2025-5270P3HIGHCVSS 7.5fixed in firefox 139.0-1 (sid)2025
CVE-2025-5270 [HIGH] CVE-2025-5270: firefox - In certain cases, SNI could have been sent unencrypted even when encrypted DNS w...
In certain cases, SNI could have been sent unencrypted even when encrypted DNS was enabled. This vulnerability affects Firefox < 139 and Thunderbird < 139.
Scope: local
sid: resolved (fixed in 139.0-1)
debian
CVE-2016-1952P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1952 [HIGH] CVE-2016-1952: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2025-11153P3HIGHCVSS 7.5fixed in firefox 143.0.3-1 (sid)2025
CVE-2025-11153 [HIGH] CVE-2025-11153: firefox - JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability a...
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 143.0.3.
Scope: local
sid: resolved (fixed in 143.0.3-1)
debian
CVE-2016-2836P3HIGHCVSS 8.8fixed in firefox 48.0-1 (sid)2016
CVE-2016-2836 [HIGH] CVE-2016-2836: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to Http2Session::Shutdown and SpdySession31::Shutdown, and other vectors.
Scope: local
sid: resolv
debian
CVE-2016-1964P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1964 [HIGH] CVE-2016-1964: firefox - Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox...
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2006-2777P3HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2777 [HIGH] CVE-2006-2777: firefox - Unspecified vulnerability in Mozilla Firefox before 1.5.0.4 and SeaMonkey before...
Unspecified vulnerability in Mozilla Firefox before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to execute arbitrary code by using the nsISelectionPrivate interface of the Selection object to add a SelectionListener and create notifications that are executed in a privileged context.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2024-9403P3HIGHCVSS 7.3fixed in firefox 131.0-1 (sid)2024
CVE-2024-9403 [HIGH] CVE-2024-9403: firefox - Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of...
Memory safety bugs present in Firefox 130. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131 and Thunderbird < 131.
Scope: local
sid: resolved (fixed in 131.0-1)
debian
CVE-2017-7774P3CRITICALCVSS 9.1fixed in firefox 54.0-1 (sid)2017
CVE-2017-7774 [CRITICAL] CVE-2017-7774: firefox - Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf:...
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2018-12388P3HIGHCVSS 8.8fixed in firefox 63.0-1 (sid)2018
CVE-2018-12388 [HIGH] CVE-2018-12388: firefox - Mozilla developers and community members reported memory safety bugs present in ...
Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 63.
Scope: local
sid: resolved (fixed in 63.0-1)
debian
CVE-2019-17025P3HIGHCVSS 8.8fixed in firefox 72.0-1 (sid)2019
CVE-2019-17025 [HIGH] CVE-2019-17025: firefox - Mozilla developers reported memory safety bugs present in Firefox 71. Some of th...
Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 72.
Scope: local
sid: resolved (fixed in 72.0-1)
debian
CVE-2020-12411P3HIGHCVSS 8.8fixed in firefox 77.0-1 (sid)2020
CVE-2020-12411 [HIGH] CVE-2020-12411: firefox - Mozilla developers reported memory safety bugs present in Firefox 76. Some of th...
Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 77.
Scope: local
sid: resolved (fixed in 77.0-1)
debian
CVE-2019-11712P3HIGHCVSS 8.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11712 [HIGH] CVE-2019-11712: firefox - POST requests made by NPAPI plugins, such as Flash, that receive a status 308 re...
POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
Scope: local
sid: resolved (fixed in 68.0-1)
debian
CVE-2020-15674P3HIGHCVSS 8.8fixed in firefox 81.0-1 (sid)2020
CVE-2020-15674 [HIGH] CVE-2020-15674: firefox - Mozilla developers reported memory safety bugs present in Firefox 80. Some of th...
Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81.
Scope: local
sid: resolved (fixed in 81.0-1)
debian
CVE-2017-7807P3HIGHCVSS 8.1fixed in firefox 55.0-1 (sid)2017
CVE-2017-7807 [HIGH] CVE-2017-7807: firefox - A mechanism that uses AppCache to hijack a URL in a domain using fallback by ser...
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Scope: local
sid: resolved (fixed in 55.0-1)
debian
CVE-2016-9896P3HIGHCVSS 8.1fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9896 [HIGH] CVE-2016-9896: firefox - Use-after-free while manipulating the "navigator" object within WebVR. Note: Web...
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2017-7813P3HIGHCVSS 8.2fixed in firefox 56.0-1 (sid)2017
CVE-2017-7813 [HIGH] CVE-2017-7813: firefox - Inside the JavaScript parser, a cast of an integer to a narrower type can result...
Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usually results in a non-exploitable crash, but can leak a limited amount of information from memory if it matches JavaScript identifier syntax. This vulnerability affects Firefox < 56.
Scope: local
sid: resolved (fixed in 56.0-1)
debian