cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 75 of 78
CVE-2021-23953P4MEDIUMCVSS 4.3fixed in firefox 85.0-1 (sid)2021
CVE-2021-23953 [MEDIUM] CVE-2021-23953: firefox - If a user clicked into a specifically crafted PDF, the PDF reader could be confu... If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7. Scope: local sid: resolved (fixed in 85.0-1)
debian
CVE-2020-12399P4MEDIUMCVSS 4.4fixed in firefox 77.0-1 (sid)2020
CVE-2020-12399 [MEDIUM] CVE-2020-12399: firefox - NSS has shown timing differences when performing DSA signatures, which was explo... NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. Scope: local sid: resolved (fixed in 77.0-1)
debian
CVE-2021-29960P4MEDIUMCVSS 4.3fixed in firefox 89.0-1 (sid)2021
CVE-2021-29960 [MEDIUM] CVE-2021-29960: firefox - Firefox used to cache the last filename used for printing a file. When generatin... Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web page title. The caching and suggestion techniques combined may have lead to the title of a website visited during private browsing mode being stored on disk. This vulnerability affects Firefox < 89. Scope: local sid: resolved
debian
CVE-2021-29961P4MEDIUMCVSS 4.3fixed in firefox 89.0-1 (sid)2021
CVE-2021-29961 [MEDIUM] CVE-2021-29961: firefox - When styling and rendering an oversized `<select>` element, Firefox did not appl... When styling and rendering an oversized `` element, Firefox did not apply correct clipping which allowed an attacker to paint over the user interface. This vulnerability affects Firefox < 89. Scope: local sid: resolved (fixed in 89.0-1)
debian
CVE-2022-46877P4MEDIUMCVSS 4.3fixed in firefox 108.0-1 (sid)2022
CVE-2022-46877 [MEDIUM] CVE-2022-46877: firefox - By confusing the browser, the fullscreen notification could have been delayed or... By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108. Scope: local sid: resolved (fixed in 108.0-1)
debian
CVE-2019-11754P4MEDIUMCVSS 4.3fixed in firefox 69.0.1-1 (sid)2019
CVE-2019-11754 [MEDIUM] CVE-2019-11754: firefox - When the pointer lock is enabled by a website though requestPointerLock(), no us... When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users. This vulnerability affects Firefox < 69.0.1. Scope: local sid: resolved (fixed in 69.0.1-1)
debian
CVE-2021-43533P4MEDIUMCVSS 4.3fixed in firefox 94.0-1 (sid)2021
CVE-2021-43533 [MEDIUM] CVE-2021-43533: firefox - When parsing internationalized domain names, high bits of the characters in the ... When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects Firefox < 94. Scope: local sid: resolved (fixed in 94.0-1)
debian
CVE-2020-15668P4MEDIUMCVSS 4.3fixed in firefox 80.0-1 (sid)2020
CVE-2020-15668 [MEDIUM] CVE-2020-15668: firefox - A lock was missing when accessing a data structure and importing certificate inf... A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80. Scope: local sid: resolved (fixed in 80.0-1)
debian
CVE-2023-6871P4MEDIUMCVSS 4.3fixed in firefox 121.0-1 (sid)2023
CVE-2023-6871 [MEDIUM] CVE-2023-6871: firefox - Under certain conditions, Firefox did not display a warning when a user attempte... Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability affects Firefox < 121. Scope: local sid: resolved (fixed in 121.0-1)
debian
CVE-2023-25750P4MEDIUMCVSS 4.3fixed in firefox 111.0-1 (sid)2023
CVE-2023-25750 [MEDIUM] CVE-2023-25750: firefox - Under certain circumstances, a ServiceWorker's offline cache may have leaked to ... Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111. Scope: local sid: resolved (fixed in 111.0-1)
debian
CVE-2024-5697P4MEDIUMCVSS 4.3fixed in firefox 127.0-1 (sid)2024
CVE-2024-5697 [MEDIUM] CVE-2024-5697: firefox - A website was able to detect when a user took a screenshot of a page using the b... A website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerability affects Firefox < 127. Scope: local sid: resolved (fixed in 127.0-1)
debian
CVE-2024-6608P4MEDIUMCVSS 4.3fixed in firefox 128.0-1 (sid)2024
CVE-2024-6608 [MEDIUM] CVE-2024-6608: firefox - It was possible to move the cursor using pointerlock from an iframe. This allowe... It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128. Scope: local sid: resolved (fixed in 128.0-1)
debian
CVE-2024-6614P4MEDIUMCVSS 4.3fixed in firefox 128.0-1 (sid)2024
CVE-2024-6614 [MEDIUM] CVE-2024-6614: firefox - The frame iterator could get stuck in a loop when encountering certain wasm fram... The frame iterator could get stuck in a loop when encountering certain wasm frames leading to incorrect stack traces. This vulnerability affects Firefox < 128 and Thunderbird < 128. Scope: local sid: resolved (fixed in 128.0-1)
debian
CVE-2025-1019P4MEDIUMCVSS 4.3fixed in firefox 135.0-1 (sid)2025
CVE-2025-1019 [MEDIUM] CVE-2025-1019: firefox - The z-order of the browser windows could be manipulated to hide the fullscreen n... The z-order of the browser windows could be manipulated to hide the fullscreen notification. This could potentially be leveraged to perform a spoofing attack. This vulnerability affects Firefox < 135 and Thunderbird < 135. Scope: local sid: resolved (fixed in 135.0-1)
debian
CVE-2025-1935P4MEDIUMCVSS 4.3fixed in firefox 136.0-1 (sid)2025
CVE-2025-1935 [MEDIUM] CVE-2025-1935: firefox - A web page could trick a user into setting that site as the default handler for ... A web page could trick a user into setting that site as the default handler for a custom URL protocol. This vulnerability affects Firefox < 136, Firefox ESR < 128.8, Thunderbird < 136, and Thunderbird < 128.8. Scope: local sid: resolved (fixed in 136.0-1)
debian
CVE-2024-0749P4MEDIUMCVSS 4.3fixed in firefox 122.0-1 (sid)2024
CVE-2024-0749 [MEDIUM] CVE-2024-0749: firefox - A phishing site could have repurposed an `about:` dialog to show phishing conten... A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7. Scope: local sid: resolved (fixed in 122.0-1)
debian
CVE-2025-5266P4MEDIUMCVSS 4.3fixed in firefox 139.0-1 (sid)2025
CVE-2025-5266 [MEDIUM] CVE-2025-5266: firefox - Script elements loading cross-origin resources generated load and error events w... Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. Scope: local sid: resolved (fixed in 139.0-1)
debian
CVE-2025-5263P4MEDIUMCVSS 4.3fixed in firefox 139.0-1 (sid)2025
CVE-2025-5263 [MEDIUM] CVE-2025-5263: firefox - Error handling for script execution was incorrectly isolated from web content, w... Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, Firefox ESR < 128.11, Thunderbird < 139, and Thunderbird < 128.11. Scope: local sid: resolved (fixed in 139.0-1)
debian
CVE-2006-5464P4LOWCVSS 5.0fixed in firefox 45.0-1 (sid)2006
CVE-2006-5464 [MEDIUM] CVE-2006-5464: firefox - Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox bef... Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2006-3802P4MEDIUMCVSS 5.8fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3802 [MEDIUM] CVE-2006-3802: firefox - Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before... Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-level object. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
Debian Firefox vulnerabilities | cvebase