Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 58 of 78
CVE-2006-6501P4HIGHCVSS 6.8fixed in firefox 45.0-1 (sid)2006
CVE-2006-6501 [MEDIUM] CVE-2006-6501: firefox - Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1....
Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2018-12398P4MEDIUMCVSS 6.5fixed in firefox 63.0-1 (sid)2018
CVE-2018-12398 [MEDIUM] CVE-2018-12398: firefox - By using the reflected URL in some special resource URIs, such as chrome:, it is...
By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.
Scope: local
sid: resolved (fixed in 63.0-1)
debian
CVE-2021-43545P4MEDIUMCVSS 6.5fixed in firefox 95.0-1 (sid)2021
CVE-2021-43545 [MEDIUM] CVE-2021-43545: firefox - Using the Location API in a loop could have caused severe application hangs and ...
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Scope: local
sid: resolved (fixed in 95.0-1)
debian
CVE-2018-18494P4MEDIUMCVSS 6.5fixed in firefox 64.0-1 (sid)2018
CVE-2018-18494 [MEDIUM] CVE-2018-18494: firefox - A same-origin policy violation allowing the theft of cross-origin URL entries wh...
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
Scope: local
sid:
debian
CVE-2018-5133P4MEDIUMCVSS 6.5fixed in firefox 59.0-1 (sid)2018
CVE-2018-5133 [MEDIUM] CVE-2018-5133: firefox - If the "app.support.baseURL" preference is changed by a malicious local program ...
If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It will be executed if a user loads "chrome://browser/content/preferences/in-content/preferences.xul" directly in a tab and executes a search. This stored preference is also executed whenever an EME video player plugin di
debian
CVE-2018-18497P4MEDIUMCVSS 6.5fixed in firefox 64.0-1 (sid)2018
CVE-2018-18497 [MEDIUM] CVE-2018-18497: firefox - Limitations on the URIs allowed to WebExtensions by the browser.windows.create A...
Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.
Scope: local
sid: resolved (fixed i
debian
CVE-2020-12424P4MEDIUMCVSS 6.5fixed in firefox 78.0-1 (sid)2020
CVE-2020-12424 [MEDIUM] CVE-2020-12424: firefox - When constructing a permission prompt for WebRTC, a URI was supplied from the co...
When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission; bypassing the prompt. This vulnerability affects Firefox < 78.
Scope: local
sid: resolved (fixed in 78.0-1)
debian
CVE-2020-12425P4MEDIUMCVSS 6.5fixed in firefox 78.0-1 (sid)2020
CVE-2020-12425 [MEDIUM] CVE-2020-12425: firefox - Due to confusion processing a hyphen character in Date.parse(), a one-byte out o...
Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. This vulnerability affects Firefox < 78.
Scope: local
sid: resolved (fixed in 78.0-1)
debian
CVE-2018-12402P4MEDIUMCVSS 6.5fixed in firefox 63.0-1 (sid)2018
CVE-2018-12402 [MEDIUM] CVE-2018-12402: firefox - The internal WebBrowserPersist code does not use correct origin context for a re...
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by including resources otherwise unreachable to the malicious page, if they can convince t
debian
CVE-2017-7781P4MEDIUMCVSS 5.9fixed in firefox 55.0-1 (sid)2017
CVE-2017-7781 [MEDIUM] CVE-2017-7781: firefox - An error occurs in the elliptic curve point addition algorithm that uses mixed J...
An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can yield a result "POINT_AT_INFINITY" when it should not. A man-in-the-middle attacker could use this to interfere with a connection, resulting in an attacked party computing an incorrect shared secret. This vulnerability affects Firefox < 55.
Scope:
debian
CVE-2021-29945P4MEDIUMCVSS 6.5fixed in firefox 88.0-1 (sid)2021
CVE-2021-29945 [MEDIUM] CVE-2021-29945: firefox - The WebAssembly JIT could miscalculate the size of a return type, which could le...
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2020-15658P4MEDIUMCVSS 6.5fixed in firefox 79.0-1 (sid)2020
CVE-2020-15658 [MEDIUM] CVE-2020-15658: firefox - The code for downloading files did not properly take care of special characters,...
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
Scope: local
sid: resolved (fixed in
debian
CVE-2019-5785P4MEDIUMCVSS 6.5fixed in firefox 65.0.1-1 (sid)2019
CVE-2019-5785 [MEDIUM] CVE-2019-5785: firefox - Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 ...
Incorrect convexity calculations in Skia in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
Scope: local
sid: resolved (fixed in 65.0.1-1)
debian
CVE-2006-2778P4HIGHCVSS 5.0fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2778 [MEDIUM] CVE-2006-2778: firefox - The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 a...
The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.
Scope: local
sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2019-11748P4MEDIUMCVSS 6.5fixed in firefox 69.0-1 (sid)2019
CVE-2019-11748 [MEDIUM] CVE-2019-11748: firefox - WebRTC in Firefox will honor persisted permissions given to sites for access to ...
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This avoids the possibility of trusted WebRTC resources being invisibly embedded in web con
debian
CVE-2021-29975P4MEDIUMCVSS 6.5fixed in firefox 90.0-1 (sid)2021
CVE-2021-29975 [MEDIUM] CVE-2021-29975: firefox - Through a series of DOM manipulations, a message, over which the attacker had co...
Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain (with the new domain correctly shown in the address bar) resulting in possible user confusion. This vulnerability affects Firefox < 90.
Scope: local
sid: resolved (fixed in 90.0-1)
debian
CVE-2020-16042P4MEDIUMCVSS 6.5fixed in chromium 87.0.4280.88-0.1 (bookworm)2020
CVE-2020-16042 [MEDIUM] CVE-2020-16042: chromium - Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote ...
Uninitialized Use in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 87.0.4280.88-0.1)
bullseye: resolved (fixed in 87.0.4280.88-0.1)
forky: resolved (fixed in 87.0.4280.88-0.1)
sid: resolved (fixed in 87.0.4280.88
debian
CVE-2023-6205P4MEDIUMCVSS 6.5fixed in firefox 120.0-1 (sid)2023
CVE-2023-6205 [MEDIUM] CVE-2023-6205: firefox - It was possible to cause the use of a MessagePort after it had already been free...
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Scope: local
sid: resolved (fixed in 120.0-1)
debian
CVE-2019-11697P4MEDIUMCVSS 6.5fixed in firefox 67.0-2 (sid)2019
CVE-2019-11697 [MEDIUM] CVE-2019-11697: firefox - If the ALT and "a" keys are pressed when users receive an extension installation...
If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malicious web page could use this with spoofing on the page to trick users into installing a malicious extension. This vul
debian
CVE-2022-22742P4MEDIUMCVSS 6.5fixed in firefox 96.0-1 (sid)2022
CVE-2022-22742 [MEDIUM] CVE-2022-22742: firefox - When inserting text while in edit mode, some characters might have lead to out-o...
When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
Scope: local
sid: resolved (fixed in 96.0-1)
debian