Debian Ublock-Origin vulnerabilities

3 known vulnerabilities affecting debian/ublock-origin.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-4215LOWCVSS 2.3fixed in ublock-origin 1.62.0+dfsg-0+deb12u1 (bookworm)2025
CVE-2025-4215 [LOW] CVE-2025-4215: ublock-origin - A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been ... A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The complexity of an attack is rather high.
debian
CVE-2022-32308MEDIUMCVSS 6.1fixed in ublock-origin 1.42.0+dfsg-1 (bookworm)2022
CVE-2022-32308 [MEDIUM] CVE-2022-32308: ublock-origin - Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.... Cross Site Scripting (XSS) vulnerability in uBlock Origin extension before 1.41.1 allows remote attackers to run arbitrary code via a spoofed 'MessageSender.url' to the browser renderer process. Scope: local bookworm: resolved (fixed in 1.42.0+dfsg-1) bullseye: resolved (fixed in 1.42.0+dfsg-1~deb11u1) forky: resolved (fixed in 1.42.0+dfsg-1) sid: resolved (
debian
CVE-2021-36773HIGHCVSS 7.5fixed in ublock-origin 1.37.0+dfsg-1 (bookworm)2021
CVE-2021-36773 [HIGH] CVE-2021-36773: ublock-origin - uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth ... uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality). Scope: local bookworm: resolved (fixed in 1.37.0+dfsg-1) bullseye: resolved (fix
debian