Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 50 of 78
CVE-2019-11696P4HIGHCVSS 7.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11696 [HIGH] CVE-2019-11696: firefox - Files with the .JNLP extension used for "Java web start" applications are not tr...
Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an executable binary locally. This vulnerability affects Firefox < 67.
Scope: local
sid: resolved (fixed in 67.0-2)
debian
CVE-2006-4561P4LOWCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.7-1 (sid)2006
CVE-2006-4561 [HIGH] CVE-2006-4561: firefox - Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript ...
Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker and that has a domain name under the attacker's control, which can force the browser to drop DNS pinning and perform a ne
debian
CVE-2006-2787P4MEDIUMCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2787 [CRITICAL] CVE-2006-2787: firefox - EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote at...
EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2006-1724P4MEDIUMCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-1724 [HIGH] CVE-2006-1724: firefox - Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x befor...
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attack vectors related to DHTML.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.2-1)
debian
CVE-2018-12365P4MEDIUMCVSS 6.5fixed in firefox 61.0-1 (sid)2018
CVE-2018-12365 [MEDIUM] CVE-2018-12365: firefox - A compromised IPC child process can escape the content sandbox and list the name...
A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
Scope: local
sid: resolved (fixe
debian
CVE-2006-3113P4HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3113 [HIGH] CVE-2006-3113: firefox - Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey be...
Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via simultaneous XPCOM events, which causes a timer object to be deleted in a way that triggers memory corruption.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2016-1963P4HIGHCVSS 7.4fixed in firefox 45.0-1 (sid)2016
CVE-2016-1963 [HIGH] CVE-2016-1963: firefox - The FileReader class in Mozilla Firefox before 45.0 allows local users to gain p...
The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2816P4MEDIUMCVSS 6.5fixed in firefox 46.0-1 (sid)2016
CVE-2016-2816 [MEDIUM] CVE-2016-2816: firefox - Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Securi...
Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.
Scope: local
sid: resolved (fixed in 46.0-1)
debian
CVE-2023-6209P4MEDIUMCVSS 6.5fixed in firefox 120.0-1 (sid)2023
CVE-2023-6209 [MEDIUM] CVE-2023-6209: firefox - Relative URLs starting with three slashes were incorrectly parsed, and a path-tr...
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Scope: local
sid: resolved (fixed in 120.0-1)
debian
CVE-2020-26965P4MEDIUMCVSS 6.5fixed in firefox 83.0-1 (sid)2020
CVE-2020-26965 [MEDIUM] CVE-2020-26965: firefox - Some websites have a feature "Show Password" where clicking a button will change...
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility
debian
CVE-2025-3028P4MEDIUMCVSS 6.5fixed in firefox 137.0-1 (sid)2025
CVE-2025-3028 [MEDIUM] CVE-2025-3028: firefox - JavaScript code running while transforming a document with the XSLTProcessor cou...
JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free. This vulnerability affects Firefox < 137, Firefox ESR < 115.22, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird < 128.9.
Scope: local
sid: resolved (fixed in 137.0-1)
debian
CVE-2023-37207P4MEDIUMCVSS 6.5fixed in firefox 115.0-1 (sid)2023
CVE-2023-37207 [MEDIUM] CVE-2023-37207: firefox - A website could have obscured the fullscreen notification by using a URL with a ...
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Scope: local
sid: resolved (fixed in 115.0-1)
debian
CVE-2025-10532P4MEDIUMCVSS 6.5fixed in firefox 143.0-1 (sid)2025
CVE-2025-10532 [MEDIUM] CVE-2025-10532: firefox - Incorrect boundary conditions in the JavaScript: GC component. This vulnerabilit...
Incorrect boundary conditions in the JavaScript: GC component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2025-10529P4MEDIUMCVSS 6.5fixed in firefox 143.0-1 (sid)2025
CVE-2025-10529 [MEDIUM] CVE-2025-10529: firefox - Same-origin policy bypass in the Layout component. This vulnerability affects Fi...
Same-origin policy bypass in the Layout component. This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2026-24868P4MEDIUMCVSS 6.5fixed in firefox 147.0.2-1 (sid)2026
CVE-2026-24868 [MEDIUM] CVE-2026-24868: firefox - Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability af...
Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability affects Firefox < 147.0.2.
Scope: local
sid: resolved (fixed in 147.0.2-1)
debian
CVE-2006-3808P4MEDIUMCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3808 [HIGH] CVE-2006-3808: firefox - Mozilla Firefox before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote Proxy Au...
Mozilla Firefox before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote Proxy AutoConfig (PAC) servers to execute code with elevated privileges via a PAC script that sets the FindProxyForURL function to an eval method on a privileged object.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2017-7771P4HIGHCVSS 8.1fixed in firefox 54.0-1 (sid)2017
CVE-2017-7771 [HIGH] CVE-2017-7771: firefox - Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass:...
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.
Scope: local
sid: resolved (fixed in 54.0-1)
debian
CVE-2018-5105P4HIGHCVSS 7.8fixed in firefox 58.0-1 (sid)2018
CVE-2018-5105 [HIGH] CVE-2018-5105: firefox - WebExtensions can bypass user prompts to first save and then open an arbitrarily...
WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58.
Scope: local
sid: resolved (fixed in 58.0-1)
debian
CVE-2020-12418P4MEDIUMCVSS 6.5fixed in firefox 78.0-1 (sid)2020
CVE-2020-12418 [MEDIUM] CVE-2020-12418: firefox - Manipulating individual parts of a URL object could have caused an out-of-bounds...
Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
Scope: local
sid: resolved (fixed in 78.0-1)
debian
CVE-2006-2776P4HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2776 [HIGH] CVE-2006-2776: firefox - Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 cal...
Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian