cbcvebase.

Debian Firefox vulnerabilities

1,550 known vulnerabilities affecting debian/firefox.

Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42

Vulnerabilities

Page 8 of 78
CVE-2016-5280P3CRITICALCVSS 9.8fixed in firefox 49.0-1 (sid)2016
CVE-2016-5280 [CRITICAL] CVE-2016-5280: firefox - Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::Remove... Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text. Scope: local sid: resolved (fixed in 49.0-1)
debian
CVE-2024-2614P3HIGHCVSS 8.8fixed in firefox 124.0-1 (sid)2024
CVE-2024-2614 [HIGH] CVE-2024-2614: firefox - Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 11... Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. Scope: local sid: resolved (fixed in 12
debian
CVE-2024-3854P3HIGHCVSS 8.8fixed in firefox 125.0.1-1 (sid)2024
CVE-2024-3854 [HIGH] CVE-2024-3854: firefox - In some code patterns the JIT incorrectly optimized switch statements and genera... In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10. Scope: local sid: resolved (fixed in 125.0.1-1)
debian
CVE-2018-18498P3CRITICALCVSS 9.8fixed in firefox 64.0-1 (sid)2018
CVE-2018-18498 [CRITICAL] CVE-2018-18498: firefox - A potential vulnerability leading to an integer overflow can occur during buffer... A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64. Scope: local sid: resolved (fixed in 64.0-1)
debian
CVE-2025-8034P3HIGHCVSS 8.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8034 [HIGH] CVE-2025-8034: firefox - Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbir... Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, F
debian
CVE-2025-8035P3HIGHCVSS 8.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8035 [HIGH] CVE-2025-8035: firefox - Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefo... Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13,
debian
CVE-2025-11714P3HIGHCVSS 8.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11714 [HIGH] CVE-2025-11714: firefox - Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird... Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 144, Firefox ESR < 115.29, Firefox ESR < 140.4,
debian
CVE-2022-46872P3HIGHCVSS 8.6fixed in firefox 108.0-1 (sid)2022
CVE-2022-46872 [HIGH] CVE-2022-46872: firefox - An attacker who compromised a content process could have partially escaped the s... An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6. Scope: local sid: resolved (fixed in 108.0-1)
debian
CVE-2018-12407P3CRITICALCVSS 9.8fixed in firefox 64.0-1 (sid)2018
CVE-2018-12407 [CRITICAL] CVE-2018-12407: firefox - A buffer overflow occurs when drawing and validating elements with the ANGLE gra... A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64. Scope: local sid: resolved (fixed in 64.0-1)
debian
CVE-2026-0891P3HIGHCVSS 8.1fixed in firefox 147.0-1 (sid)2026
CVE-2026-0891 [HIGH] CVE-2026-0891: firefox - Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox ... Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 147, Firefox ESR < 140.7, Thunderbird < 147, and Thunderbird < 140.7.
debian
CVE-2018-5093P3HIGHCVSS 7.5fixed in firefox 58.0-1 (sid)2018
CVE-2018-5093 [HIGH] CVE-2018-5093: firefox - A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Tabl... A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58. Scope: local sid: resolved (fixed in 58.0-1)
debian
CVE-2018-5158P3HIGHCVSS 8.8fixed in firefox 60.0-1 (sid)2018
CVE-2018-5158 [HIGH] CVE-2018-5158: firefox - The PDF viewer does not sufficiently sanitize PostScript calculator functions, a... The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60. Scope: local sid: resolved (fixed in 60.0-1)
debian
CVE-2018-12387P3CRITICALCVSS 9.1fixed in firefox 62.0.3-1 (sid)2018
CVE-2018-12387 [CRITICAL] CVE-2018-12387: firefox - A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push w... A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2.2 and Firefox
debian
CVE-2016-2814P3HIGHCVSS 8.8fixed in firefox 46.0-1 (sid)2016
CVE-2016-2814 [HIGH] CVE-2016-2814: firefox - Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo ... Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table. Scope: local sid: resolved (fixed in 46.0-1)
debian
CVE-2025-49709P3CRITICALCVSS 9.8fixed in firefox 139.0.4-1 (sid)2025
CVE-2025-49709 [CRITICAL] CVE-2025-49709: firefox - Certain canvas operations could have lead to memory corruption. This vulnerabili... Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4. Scope: local sid: resolved (fixed in 139.0.4-1)
debian
CVE-2025-1016P3CRITICALCVSS 9.8fixed in firefox 135.0-1 (sid)2025
CVE-2025-1016 [CRITICAL] CVE-2025-1016: firefox - Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, ... Memory safety bugs present in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135, Firefox ESR < 115.20, Fi
debian
CVE-2026-2762P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2762 [CRITICAL] CVE-2026-2762: firefox - Integer overflow in the JavaScript: Standard Library component. This vulnerabili... Integer overflow in the JavaScript: Standard Library component. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8. Scope: local sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2774P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2774 [CRITICAL] CVE-2026-2774: firefox - Integer overflow in the Audio/Video component. This vulnerability affects Firefo... Integer overflow in the Audio/Video component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8. Scope: local sid: resolved (fixed in 148.0-1)
debian
CVE-2025-11708P3CRITICALCVSS 9.8fixed in firefox 144.0-1 (sid)2025
CVE-2025-11708 [CRITICAL] CVE-2025-11708: firefox - Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects ... Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4. Scope: local sid: resolved (fixed in 144.0-1)
debian
CVE-2025-14326P3CRITICALCVSS 9.8fixed in firefox 146.0-1 (sid)2025
CVE-2025-14326 [CRITICAL] CVE-2025-14326: firefox - Use-after-free in the Audio/Video: GMP component. This vulnerability affects Fir... Use-after-free in the Audio/Video: GMP component. This vulnerability affects Firefox < 146 and Thunderbird < 146. Scope: local sid: resolved (fixed in 146.0-1)
debian
Debian Firefox vulnerabilities | cvebase