Debian Firefox vulnerabilities
1,550 known vulnerabilities affecting debian/firefox.
Total CVEs
1,550
CISA KEV
11
actively exploited
Public exploits
39
Exploited in wild
20
Severity breakdown
CRITICAL333HIGH633MEDIUM542LOW42
Vulnerabilities
Page 9 of 78
CVE-2016-2811P3HIGHCVSS 8.8fixed in firefox 46.0-1 (sid)2016
CVE-2016-2811 [HIGH] CVE-2016-2811: firefox - Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worke...
Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.
Scope: local
sid: resolved (fixed in 46.0-1)
debian
CVE-2020-6463P3HIGHCVSS 8.8fixed in chromium 83.0.4103.83-1 (bookworm)2020
CVE-2020-6463 [HIGH] CVE-2020-6463: chromium - Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote...
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 83.0.4103.83-1)
bullseye: resolved (fixed in 83.0.4103.83-1)
forky: resolved (fixed in 83.0.4103.83-1)
sid: resolved (fixed in 83.0.4103.83-1)
trixie: resolved (fixed in 83.
debian
CVE-2025-8043P3CRITICALCVSS 9.8fixed in firefox 141.0-1 (sid)2025
CVE-2025-8043 [CRITICAL] CVE-2025-8043: firefox - Focus incorrectly truncated URLs towards the beginning instead of around the ori...
Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability affects Firefox < 141 and Thunderbird < 141.
Scope: local
sid: resolved (fixed in 141.0-1)
debian
CVE-2026-2781P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2781 [CRITICAL] CVE-2026-2781: firefox - Integer overflow in the Libraries component in NSS. This vulnerability affects F...
Integer overflow in the Libraries component in NSS. This vulnerability affects Firefox < 148, Firefox ESR < 140.8, Thunderbird < 148, and Thunderbird < 140.8.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2025-13022P3CRITICALCVSS 9.8fixed in firefox 145.0-1 (sid)2025
CVE-2025-13022 [CRITICAL] CVE-2025-13022: firefox - Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerabil...
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2025-13021P3CRITICALCVSS 9.8fixed in firefox 145.0-1 (sid)2025
CVE-2025-13021 [CRITICAL] CVE-2025-13021: firefox - Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerabil...
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145 and Thunderbird < 145.
Scope: local
sid: resolved (fixed in 145.0-1)
debian
CVE-2026-2797P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2797 [CRITICAL] CVE-2026-2797: firefox - Use-after-free in the JavaScript: GC component. This vulnerability affects Firef...
Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2026-2795P3CRITICALCVSS 9.8fixed in firefox 148.0-1 (sid)2026
CVE-2026-2795 [CRITICAL] CVE-2026-2795: firefox - Use-after-free in the JavaScript: GC component. This vulnerability affects Firef...
Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 148 and Thunderbird < 148.
Scope: local
sid: resolved (fixed in 148.0-1)
debian
CVE-2016-1962P3CRITICALCVSS 9.8fixed in firefox 45.0-1 (sid)2016
CVE-2016-1962 [CRITICAL] CVE-2016-1962: firefox - Use-after-free vulnerability in the mozilla::DataChannelConnection::Close functi...
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.
Scope: local
sid: resolved (fixed in 45.0-1)
debian
CVE-2005-4134P4LOWCVSS 5.0PoCfixed in firefox 1.5.dfsg+1.5.0.2-2 (sid)2005
CVE-2005-4134 [MEDIUM] CVE-2005-4134: firefox - Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows r...
Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not processed efficiently during startup. NOTE: despite initial reports, the Mozilla vendor does not believe that this is
debian
CVE-2018-5127P3HIGHCVSS 8.8fixed in firefox 59.0-1 (sid)2018
CVE-2018-5127 [HIGH] CVE-2018-5127: firefox - A buffer overflow can occur when manipulating the SVG "animatedPathSegList" thro...
A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
Scope: local
sid: resolved (fixed in 59.0-1)
debian
CVE-2021-24002P3HIGHCVSS 8.8fixed in firefox 88.0-1 (sid)2021
CVE-2021-24002 [HIGH] CVE-2021-24002: firefox - When a user clicked on an FTP URL containing encoded newline characters (%0A and...
When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
Scope: local
sid: resolved (fixed in 88.0-1)
debian
CVE-2025-4083P3CRITICALCVSS 9.1fixed in firefox 138.0-1 (sid)2025
CVE-2025-4083 [CRITICAL] CVE-2025-4083: firefox - A process isolation vulnerability in Thunderbird stemmed from improper handling ...
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird <
debian
CVE-2026-4715P3CRITICALCVSS 9.1fixed in firefox 149.0-1 (sid)2026
CVE-2026-4715 [CRITICAL] CVE-2026-4715: firefox - Uninitialized memory in the Graphics: Canvas2D component. This vulnerability aff...
Uninitialized memory in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4716P3CRITICALCVSS 9.1fixed in firefox 149.0-1 (sid)2026
CVE-2026-4716 [CRITICAL] CVE-2026-4716: firefox - Incorrect boundary conditions, uninitialized memory in the JavaScript Engine com...
Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2026-4724P3CRITICALCVSS 9.1fixed in firefox 149.0-1 (sid)2026
CVE-2026-4724 [CRITICAL] CVE-2026-4724: firefox - Undefined behavior in the Audio/Video component. This vulnerability affects Fire...
Undefined behavior in the Audio/Video component. This vulnerability affects Firefox < 149 and Thunderbird < 149.
Scope: local
sid: resolved (fixed in 149.0-1)
debian
CVE-2022-22756P3HIGHCVSS 8.8fixed in firefox 97.0-1 (sid)2022
CVE-2022-22756 [HIGH] CVE-2022-22756: firefox - If a user was convinced to drag and drop an image to their desktop or other fold...
If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
Scope: local
sid: resolved (fixed in 97.0-1)
debian
CVE-2025-10533P3HIGHCVSS 8.8fixed in firefox 143.0-1 (sid)2025
CVE-2025-10533 [HIGH] CVE-2025-10533: firefox - Integer overflow in the SVG component. This vulnerability affects Firefox < 143,...
Integer overflow in the SVG component. This vulnerability affects Firefox < 143, Firefox ESR < 115.28, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird < 140.3.
Scope: local
sid: resolved (fixed in 143.0-1)
debian
CVE-2026-2447P3LOWCVSS 8.8fixed in firefox 147.0.4-1 (sid)2026
CVE-2026-2447 [HIGH] CVE-2026-2447: firefox - Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Fi...
Heap buffer overflow in libvpx. This vulnerability affects Firefox < 147.0.4, Firefox ESR < 140.7.1, Firefox ESR < 115.32.1, Thunderbird < 140.7.2, and Thunderbird < 147.0.2.
Scope: local
sid: resolved (fixed in 147.0.4-1)
debian
CVE-2025-14329P3HIGHCVSS 8.8fixed in firefox 146.0-1 (sid)2025
CVE-2025-14329 [HIGH] CVE-2025-14329: firefox - Privilege escalation in the Netmonitor component. This vulnerability affects Fir...
Privilege escalation in the Netmonitor component. This vulnerability affects Firefox < 146, Firefox ESR < 140.6, Thunderbird < 146, and Thunderbird < 140.6.
Scope: local
sid: resolved (fixed in 146.0-1)
debian