Debian Firefox vulnerabilities

1,810 known vulnerabilities affecting debian/firefox.

Total CVEs
1,810
CISA KEV
11
actively exploited
Public exploits
35
Exploited in wild
15
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW302

Vulnerabilities

Page 56 of 91
CVE-2019-9800CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-9800 [CRITICAL] CVE-2019-9800: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR <
debian
CVE-2019-9788CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9788 [CRITICAL] CVE-2019-9788: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox
debian
CVE-2019-9795CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9795 [CRITICAL] CVE-2019-9795: firefox - A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compile... A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66. Scope: local sid: resolved (fixed in 66.0-1)
debian
CVE-2019-9805CRITICALCVSS 9.8fixed in firefox 66.0-1 (sid)2019
CVE-2019-9805 [CRITICAL] CVE-2019-9805: firefox - A latent vulnerability exists in the Prio library where data may be read from un... A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66. Scope: local sid: resolved (fixed in 66.0-1)
debian
CVE-2019-11692CRITICALCVSS 9.8fixed in firefox 67.0-2 (sid)2019
CVE-2019-11692 [CRITICAL] CVE-2019-11692: firefox - A use-after-free vulnerability can occur when listeners are removed from the eve... A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7. Scope: local sid: resolved (fixed in 67.0-2)
debian
CVE-2019-11733CRITICALCVSS 9.8fixed in firefox 68.0.2-1 (sid)2019
CVE-2019-11733 [CRITICAL] CVE-2019-11733: firefox - When a master password is set, it is required to be entered again before stored ... When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering the master password if the master password had been previously entered in the same sess
debian
CVE-2019-11734CRITICALCVSS 9.8fixed in firefox 69.0-1 (sid)2019
CVE-2019-11734 [CRITICAL] CVE-2019-11734: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69. Scope: local sid: resolved (fixed in 69.0-1)
debian
CVE-2019-9792CRITICALCVSS 9.8PoCfixed in firefox 66.0-1 (sid)2019
CVE-2019-9792 [CRITICAL] CVE-2019-9792: firefox - The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT ... The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66. Scope: local sid: res
debian
CVE-2019-11714CRITICALCVSS 9.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11714 [CRITICAL] CVE-2019-11714: firefox - Necko can access a child on the wrong thread during UDP connections, resulting i... Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68. Scope: local sid: resolved (fixed in 68.0-1)
debian
CVE-2019-11709CRITICALCVSS 9.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11709 [CRITICAL] CVE-2019-11709: firefox - Mozilla developers and community members reported memory safety bugs present in ... Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. Scope: loc
debian
CVE-2019-17012HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17012 [HIGH] CVE-2019-17012: firefox - Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox... Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed
debian
CVE-2019-17011HIGHCVSS 7.5fixed in firefox 71.0-1 (sid)2019
CVE-2019-17011 [HIGH] CVE-2019-17011: firefox - Under certain conditions, when retrieving a document from a DocShell in the anti... Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-17013HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17013 [HIGH] CVE-2019-17013: firefox - Mozilla developers reported memory safety bugs present in Firefox 70. Some of th... Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-9799HIGHCVSS 7.5fixed in firefox 66.0-1 (sid)2019
CVE-2019-9799 [HIGH] CVE-2019-9799: firefox - Insufficient bounds checking of data during inter-process communication might al... Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66. Scope: local sid: resolved (fixed in 66.0-1)
debian
CVE-2019-11711HIGHCVSS 8.8fixed in firefox 68.0-1 (sid)2019
CVE-2019-11711 [HIGH] CVE-2019-11711: firefox - When an inner window is reused, it does not consider the use of document.domain ... When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerabil
debian
CVE-2019-17014HIGHCVSS 7.4fixed in firefox 71.0-1 (sid)2019
CVE-2019-17014 [HIGH] CVE-2019-17014: firefox - If an image had not loaded correctly (such as when it is not actually an image),... If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in a cross-origin information leak. This vulnerability affects Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-11757HIGHCVSS 8.8fixed in firefox 70.0-1 (sid)2019
CVE-2019-11757 [HIGH] CVE-2019-11757: firefox - When following the value's prototype chain, it was possible to retain a referenc... When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2019-17026HIGHCVSS 8.8KEVPoCfixed in firefox 72.0.1-1 (sid)2019
CVE-2019-17026 [HIGH] CVE-2019-17026: firefox - Incorrect alias information in IonMonkey JIT compiler for setting array elements... Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1. Scope: local sid: resolved (fixed in 72.0.1-1)
debian
CVE-2019-17005HIGHCVSS 8.8fixed in firefox 71.0-1 (sid)2019
CVE-2019-17005 [HIGH] CVE-2019-17005: firefox - The plain text serializer used a fixed-size array for the number of <ol> element... The plain text serializer used a fixed-size array for the number of elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71. Scope: local sid: resolved (fixed in 71.0-1)
debian
CVE-2019-5849HIGHCVSS 8.1fixed in chromium 76.0.3809.87-1 (bookworm)2019
CVE-2019-5849 [HIGH] CVE-2019-5849: chromium - Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remo... Out of bounds read in Skia in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. Scope: local bookworm: resolved (fixed in 76.0.3809.87-1) bullseye: resolved (fixed in 76.0.3809.87-1) forky: resolved (fixed in 76.0.3809.87-1) sid: resolved (fixed in 76.0.3809.87-1) tri
debian