Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 74 of 78
CVE-2021-23963P4MEDIUMCVSS 4.3fixed in firefox 85.0-1 (sid)2021
CVE-2021-23963 [MEDIUM] CVE-2021-23963: firefox - When sharing geolocation during an active WebRTC share, Firefox could have reset...
When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85.
Scope: local
sid: resolved (fixed in 85.0-1)
debian
CVE-2022-26383P4MEDIUMCVSS 4.3fixed in firefox 98.0-1 (sid)2022
CVE-2022-26383 [MEDIUM] CVE-2022-26383: firefox - When resizing a popup after requesting fullscreen access, the popup would not di...
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
Scope: local
sid: resolved (fixed in 98.0-1)
debian
CVE-2023-32212P4MEDIUMCVSS 4.3fixed in firefox 113.0-1 (sid)2023
CVE-2023-32212 [MEDIUM] CVE-2023-32212: firefox - An attacker could have positioned a `datalist` element to obscure the address ba...
An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
Scope: local
sid: resolved (fixed in 113.0-1)
debian
CVE-2023-32205P4MEDIUMCVSS 4.3fixed in firefox 113.0-1 (sid)2023
CVE-2023-32205 [MEDIUM] CVE-2023-32205: firefox - In multiple cases browser prompts could have been obscured by popups controlled ...
In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
Scope: local
sid: resolved (fixed in 113.0-1)
debian
CVE-2024-0742P4MEDIUMCVSS 4.3fixed in firefox 122.0-1 (sid)2024
CVE-2024-0742 [MEDIUM] CVE-2024-0742: firefox - It was possible for certain browser prompts and dialogs to be activated or dismi...
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
Scope: local
sid: resolved (fixed in 122.0-1)
debian
CVE-2023-5729P4MEDIUMCVSS 4.3fixed in firefox 119.0-1 (sid)2023
CVE-2023-5729 [MEDIUM] CVE-2023-5729: firefox - A malicious web site can enter fullscreen mode while simultaneously triggering a...
A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack. This vulnerability affects Firefox < 119.
Scope: local
sid: resolved (fixed in 119.0-1)
debian
CVE-2022-34472P4MEDIUMCVSS 4.3fixed in firefox 102.0-1 (sid)2022
CVE-2022-34472 [MEDIUM] CVE-2022-34472: firefox - If there was a PAC URL set and the server that hosts the PAC was not reachable, ...
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
Scope: local
sid: resolved (fixed in 102.0-1)
debian
CVE-2023-29533P4MEDIUMCVSS 4.3fixed in firefox 112.0-1 (sid)2023
CVE-2023-29533 [MEDIUM] CVE-2023-29533: firefox - A website could have obscured the fullscreen notification by using a combination...
A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird
debian
CVE-2022-26382P4MEDIUMCVSS 4.3fixed in firefox 98.0-1 (sid)2022
CVE-2022-26382 [MEDIUM] CVE-2022-26382: firefox - While the text displayed in Autofill tooltips cannot be directly read by JavaScr...
While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.
Scope: local
sid: resolved (fixed in 98.0-1)
debian
CVE-2024-5689P4MEDIUMCVSS 4.3fixed in firefox 127.0-1 (sid)2024
CVE-2024-5689 [MEDIUM] CVE-2024-5689: firefox - In addition to detecting when a user was taking a screenshot (XXX), a website wa...
In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.
Scope: local
sid: resolved (fixed in 127.0-1)
debian
CVE-2023-29538P4MEDIUMCVSS 4.3fixed in firefox 112.0-1 (sid)2023
CVE-2023-29538 [MEDIUM] CVE-2023-29538: firefox - Under specific circumstances a WebExtension may have received a <code>jar:file:/...
Under specific circumstances a WebExtension may have received a jar:file:/// URI instead of a moz-extension:/// URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Scope: local
sid: resolved (fixed in 112.0-1)
debian
CVE-2024-11701P4MEDIUMCVSS 4.3fixed in firefox 133.0-1 (sid)2024
CVE-2024-11701 [MEDIUM] CVE-2024-11701: firefox - The incorrect domain may have been displayed in the address bar during an interr...
The incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133 and Thunderbird < 133.
Scope: local
sid: resolved (fixed in 133.0-1)
debian
CVE-2026-0887P4MEDIUMCVSS 4.3fixed in firefox 147.0-1 (sid)2026
CVE-2026-0887 [MEDIUM] CVE-2026-0887: firefox - Clickjacking issue, information disclosure in the PDF Viewer component. This vul...
Clickjacking issue, information disclosure in the PDF Viewer component. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
Scope: local
sid: resolved (fixed in 147.0-1)
debian
CVE-2022-29915P4MEDIUMCVSS 4.3fixed in firefox 100.0-1 (sid)2022
CVE-2022-29915 [MEDIUM] CVE-2022-29915: firefox - The Performance API did not properly hide the fact whether a request cross-origi...
The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.
Scope: local
sid: resolved (fixed in 100.0-1)
debian
CVE-2025-6434P4MEDIUMCVSS 4.3fixed in firefox 140.0-1 (sid)2025
CVE-2025-6434 [MEDIUM] CVE-2025-6434: firefox - The exception page for the HTTPS-Only feature, displayed when a website is opene...
The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140 and Thunderbird < 140.
Scope: local
sid: resolved (fixed in 140.0-1)
debian
CVE-2022-36315P4MEDIUMCVSS 4.3fixed in firefox 103.0-1 (sid)2022
CVE-2022-36315 [MEDIUM] CVE-2022-36315: firefox - When loading a script with Subresource Integrity, attackers with an injection ca...
When loading a script with Subresource Integrity, attackers with an injection capability could trigger the reuse of previously cached entries with incorrect, different integrity metadata. This vulnerability affects Firefox < 103.
Scope: local
sid: resolved (fixed in 103.0-1)
debian
CVE-2016-1955P4MEDIUMCVSS 4.3fixed in firefox 45.0-1 (sid)2016
CVE-2016-1955 [MEDIUM] CVE-2016-1955: firefox - Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Po...
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2017-5451P4MEDIUMCVSS 4.3fixed in firefox 52.0.1-1 (sid)2017
CVE-2017-5451 [MEDIUM] CVE-2017-5451: firefox - A mechanism to spoof the addressbar through the user interaction on the addressb...
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
Scope: local
sid: re
debian
CVE-2016-2830P4MEDIUMCVSS 4.3fixed in firefox 48.0-1 (sid)2016
CVE-2016-2830 [MEDIUM] CVE-2016-2830: firefox - Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the networ...
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the network connection used for favicon resource retrieval after the associated browser window is closed, which makes it easier for remote web servers to track users by observing network traffic from multiple IP addresses.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2018-5167P4MEDIUMCVSS 4.3fixed in firefox 60.0-1 (sid)2018
CVE-2018-5167 [MEDIUM] CVE-2018-5167: firefox - The web console and JavaScript debugger do not sanitize all output that can be h...
The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Additionally, the JavaScript debugger will display "javascript:" links, which users could be tricked into clicking by mal
debian