Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 7 of 78
CVE-2017-5461P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5461 [CRITICAL] CVE-2017-5461: firefox - Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x bef...
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2025-6427P3CRITICALCVSS 9.1fixed in firefox 140.0-1 (sid)2025
CVE-2025-6427 [CRITICAL] CVE-2025-6427: firefox - An attacker was able to bypass the `connect-src` directive of a Content Security...
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability affects Firefox < 140 and Thunderbird < 140.
Scope: local
sid: resolved (fixed in 140.0-1)
debian
CVE-2024-11697P3HIGHCVSS 8.8fixed in firefox 133.0-1 (sid)2024
CVE-2024-11697 [HIGH] CVE-2024-11697: firefox - When handling keypress events, an attacker may have been able to trick a user in...
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
Scope: local
sid: resolved (fixed in 133.0-1)
debian
CVE-2018-5146P3HIGHCVSS 8.8fixed in firefox 59.0.1-1 (sid)2018
CVE-2018-5146 [HIGH] CVE-2018-5146: firefox - An out of bounds memory write while processing Vorbis audio data was reported th...
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
Scope: local
sid: resolved (fixed in 59.0.1-1)
debian
CVE-2017-5456P3CRITICALCVSS 9.8fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5456 [CRITICAL] CVE-2017-5456: firefox - A mechanism to bypass file system access protections in the sandbox using the fi...
A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
Scope: local
sid: resolved (fixed in 52.0.1-1)
debian
CVE-2025-14333P3HIGHCVSS 8.1fixed in firefox 146.0-1 (sid)2025
CVE-2025-14333 [HIGH] CVE-2025-14333: firefox - Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox ...
Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6
debian
CVE-2017-5391P3CRITICALCVSS 9.8fixed in firefox 51.0-1 (sid)2017
CVE-2017-5391 [CRITICAL] CVE-2017-5391: firefox - Special "about:" pages used by web content, such as RSS feeds, can load privileg...
Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.
Scope: local
sid: resolved (fixed in 51.0-1)
debian
CVE-2016-1950P3HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1950 [HIGH] CVE-2016-1950: firefox - Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.1...
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2025-1009P3CRITICALCVSS 9.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1009 [CRITICAL] CVE-2025-1009: firefox - An attacker could have caused a use-after-free via crafted XSLT data, leading to...
An attacker could have caused a use-after-free via crafted XSLT data, leading to a potentially exploitable crash. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Firefox ESR < 128.7, Thunderbird < 128.7, and Thunderbird < 135.
Scope: local
sid: resolved (fixed in 135.0-1)
debian
CVE-2026-2796P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2796 [CRITICAL] CVE-2026-2796: firefox - JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability ...
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2771P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2771 [CRITICAL] CVE-2026-2771: firefox - Undefined behavior in the DOM: Core & HTML component. This vulnerability affects...
Undefined behavior in the DOM: Core & HTML component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-0892P3CRITICALCVSS 9.8fixed in firefox 147.0-1 (sid)2026
CVE-2026-0892 [CRITICAL] CVE-2026-0892: firefox - Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bug...
Memory safety bugs present in Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147 and Thunderbird < 147.
Scope: local
sid: resolved (fixed in 147.0-1)
debian
CVE-2024-1554P3CRITICALCVSS 9.8fixed in firefox 123.0-1 (sid)2024
CVE-2024-1554 [CRITICAL] CVE-2024-1554: firefox - The `fetch()` API and navigation incorrectly shared the same cache, as the cache...
The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user wou
debian
CVE-2026-2785P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2785 [CRITICAL] CVE-2026-2785: firefox - Invalid pointer in the JavaScript Engine component. This vulnerability affects F...
Invalid pointer in the JavaScript Engine component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2025-13023P3CRITICALCVSS 9.8fixed in firefox 145.0-1 (sid)2025
CVE-2025-13023 [CRITICAL] CVE-2025-13023: firefox - Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU comp...
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2025-13026P3CRITICALCVSS 9.8fixed in firefox 145.0-1 (sid)2025
CVE-2025-13026 [CRITICAL] CVE-2025-13026: firefox - Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU comp...
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2026-4729P3CRITICALCVSS 9.8fixed in firefox 149.0-1 (sid)2026
CVE-2026-4729 [CRITICAL] CVE-2026-4729: firefox - Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bug...
Memory safety bugs present in Firefox 148 and Thunderbird 148. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 149 and Thunderbird < 149.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-2799P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2799 [CRITICAL] CVE-2026-2799: firefox - Use-after-free in the DOM: Core & HTML component. This vulnerability affects Fir...
Use-after-free in the DOM: Core & HTML component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2807P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2807 [CRITICAL] CVE-2026-2807: firefox - Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bug...
Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 148 and Thunderbird < 148.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2025-6436P3HIGHCVSS 8.1fixed in firefox 140.0-1 (sid)2025
CVE-2025-6436 [HIGH] CVE-2025-6436: firefox - Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bug...
Memory safety bugs present in Firefox 139 and Thunderbird 139. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 140 and Thunderbird < 140.
Scope: local
sid: resolved (fixed in 140.0-1)
debian