Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 55 of 78
CVE-2022-38472P4MEDIUMCVSS 6.5fixed in firefox 104.0-1 (sid)2022
CVE-2022-38472 [MEDIUM] CVE-2022-38472: firefox - An attacker could have abused XSLT error handling to associate attacker-controll...
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Fir
debian
CVE-2025-9181P4MEDIUMCVSS 6.5fixed in firefox 142.0-1 (sid)2025
CVE-2025-9181 [MEDIUM] CVE-2025-9181: firefox - Uninitialized memory in the JavaScript Engine component. This vulnerability affe...
Uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 142, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
Scope: local
sid: resolved (fixed in 142.0-1)
debian
CVE-2016-5288P4MEDIUMCVSS 5.9fixed in firefox 50.0-1 (sid)2016
CVE-2016-5288 [MEDIUM] CVE-2016-5288: firefox - Web content could access information in the HTTP cache if e10s is disabled. This...
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2022-34471P4MEDIUMCVSS 6.5fixed in firefox 102.0-1 (sid)2022
CVE-2022-34471 [MEDIUM] CVE-2022-34471: firefox - When downloading an update for an addon, the downloaded addon update's version w...
When downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifest. If the manifest had been tampered with on the server, an attacker could trick the browser into downgrading the addon to a prior version. This vulnerability affects Firefox < 102.
Scope: local
sid: resolved (fixed in 102.0
debian
CVE-2026-4728P4MEDIUMCVSS 6.5fixed in firefox 149.0-1 (sid)2026
CVE-2026-4728 [MEDIUM] CVE-2026-4728: firefox - Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability affec...
Spoofing issue in the Privacy: Anti-Tracking component. This vulnerability affects Firefox < 149 and Thunderbird < 149.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2006-3809P4MEDIUMCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3809 [HIGH] CVE-2006-3809: firefox - Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before...
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows scripts with the UniversalBrowserRead privilege to gain UniversalXPConnect privileges and possibly execute code or obtain sensitive data by reading into a privileged context.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2019-11727P4LOWCVSS 5.3fixed in firefox 68.0-1 (sid)2019
CVE-2019-11727 [MEDIUM] CVE-2019-11727: firefox - A vulnerability exists where it possible to force Network Security Services (NSS...
A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.
Scope: local
sid: resolved (fixed in 68.0
debian
CVE-2016-1967P4MEDIUMCVSS 5.0fixed in firefox 45.0-1 (sid)2016
CVE-2016-1967 [MEDIUM] CVE-2016-1967: firefox - Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAM...
Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because
debian
CVE-2018-12366P4MEDIUMCVSS 6.5fixed in firefox 61.0-1 (sid)2018
CVE-2018-12366 [MEDIUM] CVE-2018-12366: firefox - An invalid grid size during QCMS (color profile) transformations can result in t...
An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
Scope: local
sid: resolved (fixed in 61.0-1)
debian
CVE-2017-7830P4MEDIUMCVSS 6.5fixed in firefox 57.0-1 (sid)2017
CVE-2017-7830 [MEDIUM] CVE-2017-7830: firefox - The Resource Timing API incorrectly revealed navigations in cross-origin iframes...
The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs loaded by users. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
Scope: local
sid: resolved (fixed in 57.0-1)
debian
CVE-2006-1529P4MEDIUMCVSS 7.5fixed in firefox 1.5.0.2-1 (sid)2006
CVE-2006-1529 [HIGH] CVE-2006-1529: firefox - Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonk...
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530,
debian
CVE-2016-9067P4MEDIUMCVSS 6.5fixed in firefox 50.0-1 (sid)2016
CVE-2016-9067 [MEDIUM] CVE-2016-9067: firefox - Two use-after-free errors during DOM operations resulting in potentially exploit...
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2019-11742P4MEDIUMCVSS 6.5fixed in firefox 69.0-1 (sid)2019
CVE-2019-11742 [MEDIUM] CVE-2019-11742: firefox - A same-origin policy violation occurs allowing the theft of cross-origin images ...
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow for data theft. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firef
debian
CVE-2021-43536P4MEDIUMCVSS 6.5fixed in firefox 95.0-1 (sid)2021
CVE-2021-43536 [MEDIUM] CVE-2021-43536: firefox - Under certain circumstances, asynchronous functions could have caused a navigati...
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Scope: local
sid: resolved (fixed in 95.0-1)
debian
CVE-2018-12385P4HIGHCVSS 7.0fixed in firefox 62.0.2-1 (sid)2018
CVE-2018-12385 [HIGH] CVE-2018-12385: firefox - A potentially exploitable crash in TransportSecurityInfo used for SSL can be tri...
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup c
debian
CVE-2018-5132P4MEDIUMCVSS 6.5fixed in firefox 59.0-1 (sid)2018
CVE-2018-5132 [MEDIUM] CVE-2018-5132: firefox - The Find API for WebExtensions can search some privileged pages, such as "about:...
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.
Scope: local
sid: resolved (fixed in 59.0-1)
debian
CVE-2006-1531P4MEDIUMCVSS 7.5fixed in firefox 1.5.0.2 (sid)2006
CVE-2006-1531 [HIGH] CVE-2006-1531: firefox - Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonk...
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530,
debian
CVE-2006-1530P4MEDIUMCVSS 7.5fixed in firefox 1.5.0.2 (sid)2006
CVE-2006-1530 [HIGH] CVE-2006-1530: firefox - Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonk...
Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530,
debian
CVE-2020-12415P4MEDIUMCVSS 6.5fixed in firefox 78.0-1 (sid)2020
CVE-2020-12415 [MEDIUM] CVE-2020-12415: firefox - When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have b...
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.
Scope: local
sid: resolved (fixed in 78.0-1)
debian
CVE-2020-15666P4MEDIUMCVSS 6.5fixed in firefox 80.0-1 (sid)2020
CVE-2020-15666 [MEDIUM] CVE-2020-15666: firefox - When trying to load a non-video in an audio/video context the exact status code ...
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or device discovery on a local network among other atta
debian