Debian Firefox vulnerabilities
1,810 known vulnerabilities affecting debian/firefox.
Total CVEs
1,810
CISA KEV
11
actively exploited
Public exploits
35
Exploited in wild
15
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW302
Vulnerabilities
Page 79 of 91
CVE-2016-5256CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5256 [CRITICAL] CVE-2016-5256: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2016-5276CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5276 [CRITICAL] CVE-2016-5276: firefox - Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalid...
Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an aria-owns attribute.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2016-9080CRITICALCVSS 9.8fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9080 [CRITICAL] CVE-2016-9080: firefox - Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed ev...
Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2016-5254CRITICALCVSS 9.8fixed in firefox 48.0-1 (sid)2016
CVE-2016-5254 [CRITICAL] CVE-2016-5254: firefox - Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozil...
Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) by leveraging keyboard access to use the Alt key during selection of top-level menu items.
Scope: local
sid: re
debian
CVE-2016-5287CRITICALCVSS 9.8fixed in firefox 50.0-1 (sid)2016
CVE-2016-5287 [CRITICAL] CVE-2016-5287: firefox - A potentially exploitable use-after-free crash during actor destruction with ser...
A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.
Scope: local
sid: resolved (fixed in 50.0-1)
debian
CVE-2016-9063CRITICALCVSS 9.8fixed in expat 2.2.0-2 (bookworm)2016
CVE-2016-9063 [CRITICAL] CVE-2016-9063: expat - An integer overflow during the parsing of XML using the Expat library. This vuln...
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
Scope: local
bookworm: resolved (fixed in 2.2.0-2)
bullseye: resolved (fixed in 2.2.0-2)
forky: resolved (fixed in 2.2.0-2)
sid: resolved (fixed in 2.2.0-2)
trixie: resolved (fixed in 2.2.0-2)
debian
CVE-2016-5270CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5270 [CRITICAL] CVE-2016-5270: firefox - Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString...
Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to cause a denial of service (boolean out-of-bounds write) or possibly have unspecified other impact via Unicode characters that are mishandled during text conversion.
debian
CVE-2016-1962CRITICALCVSS 9.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1962 [CRITICAL] CVE-2016-1962: firefox - Use-after-free vulnerability in the mozilla::DataChannelConnection::Close functi...
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-9898CRITICALCVSS 9.8fixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9898 [CRITICAL] CVE-2016-9898: firefox - Use-after-free resulting in potentially exploitable crash when manipulating DOM ...
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2016-9899CRITICALCVSS 9.8PoCfixed in firefox 50.1.0-1 (sid)2016
CVE-2016-9899 [CRITICAL] CVE-2016-9899: firefox - Use-after-free while manipulating DOM events and removing audio elements due to ...
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Scope: local
sid: resolved (fixed in 50.1.0-1)
debian
CVE-2016-5280CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5280 [CRITICAL] CVE-2016-5280: firefox - Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::Remove...
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2016-5257CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5257 [CRITICAL] CVE-2016-5257: firefox - Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox be...
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Scope: local
sid: resolved (fixed in 49.0-1)
debian
CVE-2016-1950HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1950 [HIGH] CVE-2016-1950: firefox - Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.1...
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-9078HIGHCVSS 8.8fixed in firefox 50.0.2-1 (sid)2016
CVE-2016-9078 [HIGH] CVE-2016-9078: firefox - Redirection from an HTTP connection to a "data:" URL assigns the referring site'...
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Firefox 49 and 50.
debian
CVE-2016-2796HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2796 [HIGH] CVE-2016-2796: firefox - Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in...
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2799HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2799 [HIGH] CVE-2016-2799: firefox - Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite ...
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-2797HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-2797 [HIGH] CVE-2016-2797: firefox - The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6...
The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801.
Scope: local
sid: re
debian
CVE-2016-1979HIGHCVSS 8.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1979 [HIGH] CVE-2016-1979: firefox - Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey fun...
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2016-5264HIGHCVSS 8.8fixed in firefox 48.0-1 (sid)2016
CVE-2016-5264 [HIGH] CVE-2016-5264: firefox - Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange ...
Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG element that is mishandled during effect application.
Scope: local
sid: resolved (fixed in 48.0-1)
debian
CVE-2016-2812HIGHCVSS 7.5fixed in firefox 46.0-1 (sid)2016
CVE-2016-2812 [HIGH] CVE-2016-2812: firefox - Race condition in the get implementation in the ServiceWorkerManager class in th...
Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site.
Scope: local
sid: resolved (fixed in 46.0-1)
debian