Debian Firefox vulnerabilities

1,810 known vulnerabilities affecting debian/firefox.

Total CVEs
1,810
CISA KEV
11
actively exploited
Public exploits
35
Exploited in wild
15
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW302

Vulnerabilities

Page 88 of 91
CVE-2006-2780HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2780 [CRITICAL] CVE-2006-2780: firefox - Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote... Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2006-3806HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3806 [HIGH] CVE-2006-3806: firefox - Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.... Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSource method of the Object, Array, and String objects; and (2) unspecified "string function arguments." Scope: local sid: re
debian
CVE-2006-1735HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1735 [CRITICAL] CVE-2006-1735: firefox - Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla S... Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.2-2)
debian
CVE-2006-1730HIGHCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-1 (sid)2006
CVE-2006-1730 [CRITICAL] CVE-2006-1730: firefox - Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x... Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via a large number in the CSS letter-spacing property that leads to a heap-based buffer overflow. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.2-1)
debian
CVE-2006-5462HIGHCVSS 4.0fixed in firefox 45.0-1 (sid)2006
CVE-2006-5462 [MEDIUM] CVE-2006-5462: firefox - Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla... Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature, which allows remote attackers to forge signatures for SSL/TLS and email certificates. NOTE: this identifier is for u
debian
CVE-2006-3801HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3801 [HIGH] CVE-2006-3801: firefox - Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly ... Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 does not properly clear a JavaScript reference to a frame or window, which leaves a pointer to a deleted object that allows remote attackers to execute arbitrary native code. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian
CVE-2006-5463HIGHCVSS 7.5fixed in firefox 45.0-1 (sid)2006
CVE-2006-5463 [HIGH] CVE-2006-5463: firefox - Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before ... Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object while it is executing. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2006-3811HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3811 [HIGH] CVE-2006-3811: firefox - Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1... Multiple vulnerabilities in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Javascript that leads to memory corruption, including (1) nsListControlFrame::FireMenuItemActiveEvent, (2) buffer overflows in the string class in out-of-m
debian
CVE-2006-3803HIGHCVSS 5.1fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3803 [MEDIUM] CVE-2006-3803: firefox - Race condition in the JavaScript garbage collection in Mozilla Firefox 1.5 befor... Race condition in the JavaScript garbage collection in Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code by causing the garbage collector to delete a temporary variable while it is still being used during the creation of a new Function object. Scope: local sid: resolved (
debian
CVE-2006-2776HIGHCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2776 [HIGH] CVE-2006-2776: firefox - Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 cal... Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2006-4310MEDIUMCVSS 4.3PoCfixed in firefox 45.0-1 (sid)2006
CVE-2006-4310 [MEDIUM] CVE-2006-4310: firefox - Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (cr... Mozilla Firefox 1.5.0.6 allows remote attackers to cause a denial of service (crash) via a crafted FTP response, when attempting to connect with a username and password via the FTP URI. Scope: local sid: resolved (fixed in 45.0-1)
debian
CVE-2006-1742MEDIUMCVSS 5.0fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1742 [MEDIUM] CVE-2006-1742: firefox - The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.... The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption. Scope: local sid: resolved (fixed in 1.
debian
CVE-2006-1731MEDIUMCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1731 [MEDIUM] CVE-2006-1731: firefox - Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla S... Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks. Scope: local sid
debian
CVE-2006-1723MEDIUMCVSS 7.5fixed in firefox 1.5.dfsg+1.5.0.2 (sid)2006
CVE-2006-1723 [HIGH] CVE-2006-1723: firefox - Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonk... Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530,
debian
CVE-2006-2786MEDIUMCVSS 2.6fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2786 [LOW] CVE-2006-2786: firefox - HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before ... HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites via (1) invalid HTTP response headers with spaces between the header name and the colon, which might not be ignored in so
debian
CVE-2006-1739MEDIUMCVSS 9.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1739 [CRITICAL] CVE-2006-1739: firefox - The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 ... The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow. Scope: l
debian
CVE-2006-1741MEDIUMCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2006
CVE-2006-1741 [MEDIUM] CVE-2006-1741: firefox - Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.... Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__
debian
CVE-2006-2783MEDIUMCVSS 4.3fixed in firefox 1.5.dfsg+1.5.0.4-1 (sid)2006
CVE-2006-2783 [MEDIUM] CVE-2006-2783: firefox - Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark... Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.4-1)
debian
CVE-2006-1529MEDIUMCVSS 7.5fixed in firefox 1.5.0.2-1 (sid)2006
CVE-2006-1529 [HIGH] CVE-2006-1529: firefox - Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonk... Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors related to DHTML. NOTE: due to the lack of sufficient public details from the vendor as of 20060413, it is unclear how CVE-2006-1529, CVE-2006-1530,
debian
CVE-2006-3812MEDIUMCVSS 2.6fixed in firefox 1.5.dfsg+1.5.0.5-1 (sid)2006
CVE-2006-3812 [LOW] CVE-2006-3812: firefox - Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before... Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links. Scope: local sid: resolved (fixed in 1.5.dfsg+1.5.0.5-1)
debian