cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 73 of 78
CVE-2023-4581P4MEDIUMCVSS 4.3fixed in firefox 117.0-1 (sid)2023
CVE-2023-4581 [MEDIUM] CVE-2023-4581: firefox - Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable... Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2. Scope: local sid: resolved (fixed in 117.0-1)
debian
CVE-2024-4767P4MEDIUMCVSS 4.3fixed in firefox 126.0-1 (sid)2024
CVE-2024-4767 [MEDIUM] CVE-2024-4767: firefox - If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB file... If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11. Scope: local sid: resolved (fixed in 126.0-1)
debian
CVE-2025-6425P4MEDIUMCVSS 4.3fixed in firefox 140.0-1 (sid)2025
CVE-2025-6425 [MEDIUM] CVE-2025-6425: firefox - An attacker who enumerated resources from the WebCompat extension could have obt... An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode, but not profiles. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, Firefox ESR < 128.12, Thunderbird < 140, and Thunderbird < 128.12. Scope: local sid: r
debian
CVE-2022-3266P4MEDIUMCVSS 5.5fixed in firefox 105.0-1 (sid)2022
CVE-2022-3266 [MEDIUM] CVE-2022-3266: firefox - An out-of-bounds read can occur when decoding H264 video. This results in a pote... An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105. Scope: local sid: resolved (fixed in 105.0-1)
debian
CVE-2024-6613P4MEDIUMCVSS 5.5fixed in firefox 128.0-1 (sid)2024
CVE-2024-6613 [MEDIUM] CVE-2024-6613: firefox - The frame iterator could get stuck in a loop when encountering certain wasm fram... The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128. Scope: local sid: resolved (fixed in 128.0-1)
debian
CVE-2016-1958P4MEDIUMCVSS 4.3fixed in firefox 45.0-1 (sid)2016
CVE-2016-1958 [MEDIUM] CVE-2016-1958: firefox - browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 3... browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2018-12367P4MEDIUMCVSS 4.3fixed in firefox 61.0-1 (sid)2018
CVE-2018-12367 [MEDIUM] CVE-2018-12367: firefox - In the previous mitigations for Spectre, the resolution or precision of various ... In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61. Sco
debian
CVE-2018-18511P4MEDIUMCVSS 4.3fixed in firefox 65.0.1-1 (sid)2018
CVE-2018-18511 [MEDIUM] CVE-2018-18511: firefox - Cross-origin images can be read from a canvas element in violation of the same-o... Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1. Scope: local sid: resolved (fixed in 65.0.1-1)
debian
CVE-2021-43546P4MEDIUMCVSS 4.3fixed in firefox 95.0-1 (sid)2021
CVE-2021-43546 [MEDIUM] CVE-2021-43546: firefox - It was possible to recreate previous cursor spoofing attacks against users with ... It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. Scope: local sid: resolved (fixed in 95.0-1)
debian
CVE-2018-12399P4MEDIUMCVSS 4.3fixed in firefox 63.0-1 (sid)2018
CVE-2018-12399 [MEDIUM] CVE-2018-12399: firefox - When a new protocol handler is registered, the API accepts a title argument whic... When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63. Scope: local sid: resolved (fixed in 63.0-1)
debian
CVE-2020-12401P4MEDIUMCVSS 4.7fixed in firefox 80.0-1 (sid)2020
CVE-2020-12401 [MEDIUM] CVE-2020-12401: firefox - During ECDSA signature generation, padding applied in the nonce designed to ensu... During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80. Scope: local sid: resolved (fixed in 80.0-1)
debian
CVE-2006-0299P4MEDIUMCVSS 6.4fixed in firefox 1.5.dfsg+1.5.0.1-1 (sid)2006
CVE-2006-0299 [MEDIUM] CVE-2006-0299: firefox - The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if run... The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange information in violation of the same origin restrictions. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.1-1)
debian
CVE-2020-12400P4MEDIUMCVSS 4.7fixed in firefox 80.0-1 (sid)2020
CVE-2020-12400 [MEDIUM] CVE-2020-12400: firefox - When converting coordinates from projective to affine, the modular inversion was... When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80. Scope: local sid: resolved (fixed in 80.0-1)
debian
CVE-2021-23969P4MEDIUMCVSS 4.3fixed in firefox 86.0-1 (sid)2021
CVE-2021-23969 [MEDIUM] CVE-2021-23969: firefox - As specified in the W3C Content Security Policy draft, when creating a violation... As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the source f
debian
CVE-2018-5108P4MEDIUMCVSS 4.3fixed in firefox 58.0-1 (sid)2018
CVE-2018-5108 [MEDIUM] CVE-2018-5108: firefox - A Blob URL can violate origin attribute segregation, allowing it to be accessed ... A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually
debian
CVE-2021-29959P4MEDIUMCVSS 4.3fixed in firefox 89.0-1 (sid)2021
CVE-2021-29959 [MEDIUM] CVE-2021-29959: firefox - When a user has already allowed a website to access microphone and camera, disab... When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording with the microphone until re-enabling the camera. This vulnerability affects Firefox < 89. Scope: local sid: resolved (fixed in
debian
CVE-2021-29974P4MEDIUMCVSS 4.3fixed in firefox 90.0-1 (sid)2021
CVE-2021-29974 [MEDIUM] CVE-2021-29974: firefox - When network partitioning was enabled, e.g. as a result of Enhanced Tracking Pro... When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to
debian
CVE-2019-9807P4MEDIUMCVSS 4.3fixed in firefox 66.0-1 (sid)2019
CVE-2019-9807 [MEDIUM] CVE-2019-9807: firefox - When arbitrary text is sent over an FTP connection and a page reload is initiate... When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66. Scope: local sid: resolved (fixed in 66.0-1)
debian
CVE-2020-12412P4MEDIUMCVSS 4.3fixed in firefox 70.0-1 (sid)2020
CVE-2020-12412 [MEDIUM] CVE-2020-12412: firefox - By navigating a tab using the history API, an attacker could cause the address b... By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// scheme, a blocked port number such as '1', and without a lock icon) while controlling the page contents. This vulnerability affects Firefox < 70. Scope: local sid: resolved (fixed in 70.0-1)
debian
CVE-2023-6135P4MEDIUMCVSS 4.3fixed in firefox 121.0-1 (sid)2023
CVE-2023-6135 [MEDIUM] CVE-2023-6135: firefox - Multiple NSS NIST curves were susceptible to a side-channel attack known as "Min... Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121. Scope: local sid: resolved (fixed in 121.0-1)
debian
Debian Firefox vulnerabilities | cvebase