Debian Firefox vulnerabilities
1,810 known vulnerabilities affecting debian/firefox.
Total CVEs
1,810
CISA KEV
11
actively exploited
Public exploits
35
Exploited in wild
15
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW302
Vulnerabilities
Page 51 of 91
CVE-2020-6811HIGHCVSS 8.8fixed in firefox 74.0-1 (sid)2020
CVE-2020-6811 [HIGH] CVE-2020-6811: firefox - The 'Copy as cURL' feature of Devtools' network tab did not properly escape the ...
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Fire
debian
CVE-2020-26971HIGHCVSS 8.8fixed in firefox 84.0-1 (sid)2020
CVE-2020-26971 [HIGH] CVE-2020-26971: firefox - Certain blit values provided by the user were not properly constrained leading t...
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
Scope: local
sid: resolved (fixed in 84.0-1)
debian
CVE-2020-6821HIGHCVSS 7.5fixed in firefox 75.0-1 (sid)2020
CVE-2020-6821 [HIGH] CVE-2020-6821: firefox - When reading from areas partially or fully outside the source resource with WebG...
When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
Scope: local
sid: resolved
debian
CVE-2020-12410HIGHCVSS 8.8fixed in firefox 77.0-1 (sid)2020
CVE-2020-12410 [HIGH] CVE-2020-12410: firefox - Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox...
Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Scope: local
sid: resolved (fixe
debian
CVE-2020-15969HIGHCVSS 8.8fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-15969 [HIGH] CVE-2020-15969: chromium - Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote...
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88-0.1)
trixie: resolved (fi
debian
CVE-2020-6822HIGHCVSS 8.8fixed in firefox 75.0-1 (sid)2020
CVE-2020-6822 [HIGH] CVE-2020-6822: firefox - On 32-bit builds, an out of bounds write could have occurred when processing an ...
On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
Scope: local
sid: resolved (fixed in 75.0-1)
debian
CVE-2020-26969HIGHCVSS 8.8fixed in firefox 83.0-1 (sid)2020
CVE-2020-26969 [HIGH] CVE-2020-26969: firefox - Mozilla developers reported memory safety bugs present in Firefox 82. Some of th...
Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83.
Scope: local
sid: resolved (fixed in 83.0-1)
debian
CVE-2020-26950HIGHCVSS 8.8PoCfixed in firefox 82.0.3-1 (sid)2020
CVE-2020-26950 [HIGH] CVE-2020-26950: firefox - In certain circumstances, the MCallGetProperty opcode can be emitted with unmet ...
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.
Scope: local
sid: resolved (fixed in 82.0.3-1)
debian
CVE-2020-15677MEDIUMCVSS 6.1fixed in firefox 81.0-1 (sid)2020
CVE-2020-15677 [MEDIUM] CVE-2020-15677: firefox - By exploiting an Open Redirect vulnerability on a website, an attacker could hav...
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
Scope: local
si
debian
CVE-2020-12405MEDIUMCVSS 5.3fixed in firefox 77.0-1 (sid)2020
CVE-2020-12405 [MEDIUM] CVE-2020-12405: firefox - When browsing a malicious page, a race condition in our SharedWorkerService coul...
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Scope: local
sid: resolved (fixed in 77.0-1)
debian
CVE-2020-15676MEDIUMCVSS 6.1fixed in firefox 81.0-1 (sid)2020
CVE-2020-15676 [MEDIUM] CVE-2020-15676: firefox - Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer...
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
Scope: local
sid: resolved (fixed in 81.0-1)
debian
CVE-2020-26965MEDIUMCVSS 6.5fixed in firefox 83.0-1 (sid)2020
CVE-2020-26965 [MEDIUM] CVE-2020-26965: firefox - Some websites have a feature "Show Password" where clicking a button will change...
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and the possibility
debian
CVE-2020-12408MEDIUMCVSS 6.5fixed in firefox 77.0-1 (sid)2020
CVE-2020-12408 [MEDIUM] CVE-2020-12408: firefox - When browsing a document hosted on an IP address, an attacker could insert certa...
When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the address bar. This vulnerability affects Firefox < 77.
Scope: local
sid: resolved (fixed in 77.0-1)
debian
CVE-2020-15655MEDIUMCVSS 6.5fixed in firefox 79.0-1 (sid)2020
CVE-2020-15655 [MEDIUM] CVE-2020-15655: firefox - A redirected HTTP request which is observed or modified through a web extension ...
A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Scope: local
sid: resolved (fixed in 79.0-1)
debian
CVE-2020-12400MEDIUMCVSS 4.7fixed in firefox 80.0-1 (sid)2020
CVE-2020-12400 [MEDIUM] CVE-2020-12400: firefox - When converting coordinates from projective to affine, the modular inversion was...
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
Scope: local
sid: resolved (fixed in 80.0-1)
debian
CVE-2020-15652MEDIUMCVSS 6.5fixed in firefox 79.0-1 (sid)2020
CVE-2020-15652 [MEDIUM] CVE-2020-15652: firefox - By observing the stack trace for JavaScript errors in web workers, it was possib...
By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
Scope: local
sid: resolved (fixed in 79.0-1)
debian
CVE-2020-26958MEDIUMCVSS 6.1fixed in firefox 83.0-1 (sid)2020
CVE-2020-26958 [MEDIUM] CVE-2020-26958: firefox - Firefox did not block execution of scripts with incorrect MIME types when the re...
Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
Scope: local
sid: resolved (fixed in 83.0
debian
CVE-2020-12399MEDIUMCVSS 4.4fixed in firefox 77.0-1 (sid)2020
CVE-2020-12399 [MEDIUM] CVE-2020-12399: firefox - NSS has shown timing differences when performing DSA signatures, which was explo...
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
Scope: local
sid: resolved (fixed in 77.0-1)
debian
CVE-2020-12407MEDIUMCVSS 6.5fixed in firefox 77.0-1 (sid)2020
CVE-2020-12407 [MEDIUM] CVE-2020-12407: firefox - Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would u...
Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. The leaked memory content was visible to the user, but not observable from web content. This vulnerability affects Firefox < 77.
Scope: local
sid: resolved (fixed in 77.0-1)
debian
CVE-2020-12425MEDIUMCVSS 6.5fixed in firefox 78.0-1 (sid)2020
CVE-2020-12425 [MEDIUM] CVE-2020-12425: firefox - Due to confusion processing a hyphen character in Date.parse(), a one-byte out o...
Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. This vulnerability affects Firefox < 78.
Scope: local
sid: resolved (fixed in 78.0-1)
debian