firefox vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the firefox package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
HTTP Request Smuggling

*
  • L
HTTP Request Smuggling

*
  • M
Cross-site Scripting (XSS)

<0:128.12.0-1.el10_0
  • M
Use of Incorrectly-Resolved Name or Reference

<0:128.12.0-1.el10_0
  • M
Information Exposure

<0:128.12.0-1.el10_0
  • H
Use After Free

<0:128.12.0-1.el10_0
  • L
Improper Input Validation

*
  • L
Improper Resource Shutdown or Release

*
  • L
Use After Free

*
  • L
Reachable Assertion

*
  • H
Double Free

<0:128.11.0-1.el10_0
  • L
Improper Check for Unusual or Exceptional Conditions

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • M
Improper Cleanup on Thrown Exception

*
  • H
Buffer Overflow

*
  • H
Buffer Overflow

*
  • H
Use After Free

*
  • H
Use After Free

*
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • H
Out-of-bounds Read

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Heap-based Buffer Overflow

*
  • L
Race Condition

*
  • L
Improper Restriction of Rendered UI Layers or Frames

<0:128.11.0-1.el10_0
  • M
Inclusion of Functionality from Untrusted Control Sphere

<0:128.11.0-1.el10_0
  • M
Out-of-Bounds

<0:128.11.0-1.el10_0
  • M
Improper Encoding or Escaping of Output

<0:128.11.0-1.el10_0
  • M
Inclusion of Functionality from Untrusted Control Sphere

<0:128.11.0-1.el10_0
  • M
Out-of-Bounds

<0:128.11.0-1.el10_0
  • M
CVE-2025-48068

*
  • M
Improper Validation of Unsafe Equivalence in Input

*
  • H
Out-of-bounds Write

<0:128.10.1-1.el10_0
  • H
Out-of-bounds Write

<0:128.10.1-1.el10_0
  • L
Use After Free

*
  • L
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

*
  • L
Information Exposure

*
  • L
Product UI does not Warn User of Unsafe Actions

*
  • M
Double Free

*
  • M
User Interface (UI) Misrepresentation of Critical Information

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Validation of Integrity Check Value

*
  • H
Buffer Overflow

*
  • M
Incomplete Filtering of Special Elements

*
  • M
Buffer Overflow

<0:128.10.0-1.el10_0
  • M
Out-of-bounds Read

<0:128.10.0-1.el10_0
  • H
Buffer Overflow

<0:128.10.0-1.el10_0
  • H
Arbitrary Code Injection

<0:128.10.0-1.el10_0
  • H
Insufficient Compartmentalization

<0:128.10.0-1.el10_0
  • M
Origin Validation Error

<0:128.9.0-3.el10_0
  • H
Buffer Overflow

<0:128.9.0-3.el10_0
  • H
Use After Free

<0:128.9.0-3.el10_0