firefox vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the firefox package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • L
NULL Pointer Dereference

*
  • L
Out-of-bounds Read

*
  • L
Missing Synchronization

*
  • L
User Interface (UI) Misrepresentation of Critical Information

*
  • L
Double Free

*
  • M
Cross-site Scripting (XSS)

*
  • L
Product UI does not Warn User of Unsafe Actions

*
  • M
User Interface (UI) Misrepresentation of Critical Information

*
  • M
Cross-site Scripting (XSS)

*
  • M
Improper Validation of Integrity Check Value

*
  • M
User Interface (UI) Misrepresentation of Critical Information

*
  • H
Buffer Overflow

*
  • M
Resource Exhaustion

*
  • M
Out-of-bounds Read

*
  • L
CVE-2024-10941

*
  • M
Buffer Overflow

<0:128.4.0-1.el7_9
  • M
Resource Exhaustion

<0:128.4.0-1.el7_9
  • M
Improper Input Validation

<0:128.4.0-1.el7_9
  • M
Improper Control of Interaction Frequency

<0:128.4.0-1.el7_9
  • M
Overly Permissive Cross-domain Whitelist

<0:128.4.0-1.el7_9
  • M
Improper Handling of Insufficient Permissions or Privileges

<0:128.4.0-1.el7_9
  • M
Cross-site Scripting (XSS)

<0:128.4.0-1.el7_9
  • M
Improper Verification of Source of a Communication Channel

<0:128.4.0-1.el7_9
  • M
Use After Free

<0:128.4.0-1.el7_9
  • M
Improper Handling of Insufficient Permissions or Privileges

<0:128.4.0-1.el7_9
  • H
Use After Free

*
  • H
Improper Handling of Insufficient Permissions or Privileges

*
  • H
Out-of-bounds Read

<0:102.3.0-6.el7_9
  • L
Inefficient Regular Expression Complexity

*
  • H
Use After Free

<0:128.3.1-2.el7_9
  • H
Buffer Overflow

<0:128.3.0-1.el7_9
  • H
Buffer Overflow

<0:128.3.0-1.el7_9
  • H
Buffer Overflow

<0:128.3.0-1.el7_9
  • H
Uncontrolled Memory Allocation

<0:128.3.0-1.el7_9
  • H
Improper Check for Unusual or Exceptional Conditions

<0:128.3.0-1.el7_9
  • H
Information Exposure

<0:128.3.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:128.3.0-1.el7_9
  • H
Out-of-Bounds

<0:128.3.0-1.el7_9
  • H
Arbitrary Code Injection

<0:128.3.0-1.el7_9
  • H
Arbitrary Code Injection

<0:128.3.0-1.el7_9
  • H
Origin Validation Error

<0:128.3.0-1.el7_9
  • H
CVE-2024-8900

<0:128.3.0-1.el7_9
  • H
Buffer Overflow

<0:128.2.0-1.el7_9
  • H
Improperly Implemented Security Check for Standard

<0:128.2.0-1.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:128.2.0-1.el7_9
  • H
Out-of-bounds Write

<0:128.2.0-1.el7_9
  • H
Missing Authorization

<0:128.2.0-1.el7_9
  • H
Exposure of System Data to an Unauthorized Control Sphere

<0:128.2.0-1.el7_9
  • H
Incorrect Type Conversion or Cast

<0:128.2.0-1.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:128.2.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.6.0-1.el7_9
  • H
Use of Uninitialized Resource

<0:115.6.0-1.el7_9
  • H
Buffer Overflow

<0:115.6.0-1.el7_9
  • H
Improper Input Validation

<0:115.6.0-1.el7_9
  • H
Use After Free

<0:115.6.0-1.el7_9
  • H
Heap-based Buffer Overflow

<0:115.6.0-1.el7_9
  • H
Improper Input Validation

<0:115.6.0-1.el7_9
  • H
Use After Free

<0:115.6.0-1.el7_9
  • H
Heap-based Buffer Overflow

<0:115.6.0-1.el7_9
  • H
Race Condition

<0:115.6.0-1.el7_9
  • H
Heap-based Buffer Overflow

<0:115.6.0-1.el7_9
  • H
Buffer Overflow

<0:102.13.0-2.el7_9
  • H
Compilation with Insufficient Warnings or Errors

<0:102.13.0-2.el7_9
  • H
Authentication Bypass

<0:102.13.0-2.el7_9
  • H
Use After Free

<0:102.13.0-2.el7_9
  • H
Use After Free

<0:102.13.0-2.el7_9
  • H
Buffer Overflow

<0:115.8.0-1.el7_9
  • H
Incorrect Conversion between Numeric Types

<0:115.8.0-1.el7_9
  • H
Arbitrary Code Injection

<0:115.8.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.8.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.8.0-1.el7_9
  • H
The UI Performs the Wrong Action

<0:115.8.0-1.el7_9
  • H
The UI Performs the Wrong Action

<0:115.8.0-1.el7_9
  • H
Out-of-bounds Read

<0:115.8.0-1.el7_9
  • H
Buffer Overflow

<0:102.11.0-2.el7_9
  • H
Use of Uninitialized Variable

<0:102.11.0-2.el7_9
  • H
Insufficient Verification of Data Authenticity

<0:102.11.0-2.el7_9
  • H
Resource Exhaustion

<0:102.11.0-2.el7_9
  • H
Improper Handling of Insufficient Permissions or Privileges

<0:102.11.0-2.el7_9
  • H
Out-of-bounds Read

<0:102.11.0-2.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:102.11.0-2.el7_9
  • H
Buffer Overflow

<0:102.15.0-1.el7_9
  • H
Buffer Overflow

<0:102.15.0-1.el7_9
  • H
Incorrect Behavior Order: Early Validation

<0:102.15.0-1.el7_9
  • H
Compilation with Insufficient Warnings or Errors

<0:102.15.0-1.el7_9
  • H
Information Exposure

<0:102.15.0-1.el7_9
  • H
Out-of-Bounds

<0:102.15.0-1.el7_9
  • H
Resource Exhaustion

<0:102.15.0-1.el7_9
  • H
Use After Free

<0:102.15.0-1.el7_9
  • H
Use After Free

<0:102.15.0-1.el7_9
  • H
Use After Free

<0:102.15.0-1.el7_9
  • H
Authentication Bypass

<0:102.15.0-1.el7_9
  • H
Authentication Bypass

<0:102.15.0-1.el7_9
  • H
Multiple Interpretations of UI Input

<0:115.4.0-1.el7_9
  • H
Buffer Overflow

<0:115.4.0-1.el7_9
  • H
Memory Leak

<0:115.4.0-1.el7_9
  • H
Open Redirect

<0:115.4.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.4.0-1.el7_9
  • H
Product UI does not Warn User of Unsafe Actions

<0:115.4.0-1.el7_9
  • H
Improper Handling of Exceptional Conditions

<0:115.4.0-1.el7_9
  • H
Use After Free

<0:115.12.0-1.el7_9
  • H
Buffer Overflow

<0:115.12.0-1.el7_9
  • H
Improper Validation of Specified Type of Input

<0:115.12.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:115.12.0-1.el7_9
  • H
Improper Access Control

<0:115.12.0-1.el7_9
  • H
Covert Timing Channel

<0:115.12.0-1.el7_9
  • H
Use After Free

<0:115.12.0-1.el7_9
  • H
Buffer Overflow

<0:115.5.0-1.el7_9
  • H
Directory Traversal

<0:115.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.5.0-1.el7_9
  • H
Use After Free

<0:115.5.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:115.5.0-1.el7_9
  • H
Use After Free

<0:115.5.0-1.el7_9
  • H
Out-of-bounds Read

<0:115.5.0-1.el7_9
  • H
Buffer Overflow

<0:115.13.0-3.el7_9
  • H
Out-of-Bounds

<0:115.13.0-3.el7_9
  • H
Improper Preservation of Permissions

<0:115.13.0-3.el7_9
  • H
Buffer Overflow

<0:91.13.0-1.el7_9
  • H
Buffer Overflow

<0:91.13.0-1.el7_9
  • H
Use After Free

<0:91.13.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.13.0-1.el7_9
  • H
Product UI does not Warn User of Unsafe Actions

<0:91.13.0-1.el7_9
  • H
Use After Free

<0:102.6.0-1.el7_9
  • H
Out-of-Bounds

<0:102.6.0-1.el7_9
  • H
Use After Free

<0:102.6.0-1.el7_9
  • H
Buffer Overflow

<0:102.6.0-1.el7_9
  • H
Truncation of Security-relevant Information

<0:102.6.0-1.el7_9
  • H
Information Exposure

<0:102.6.0-1.el7_9
  • H
Buffer Overflow

<0:102.14.0-1.el7_9
  • H
Buffer Overflow

<0:102.14.0-1.el7_9
  • H
Reliance on Cookies without Validation and Integrity Checking in a Security Decision

<0:102.14.0-1.el7_9
  • H
Buffer Overflow

<0:102.14.0-1.el7_9
  • H
Race Condition

<0:102.14.0-1.el7_9
  • H
Out-of-bounds Read

<0:102.14.0-1.el7_9
  • H
Improper Handling of Insufficient Permissions or Privileges

<0:102.14.0-1.el7_9
  • H
Improper Input Validation

<0:102.14.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:102.14.0-1.el7_9
  • H
Buffer Overflow

<0:102.3.0-6.el7_9
  • H
Use After Free

<0:102.3.0-6.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.3.0-6.el7_9
  • H
Reliance on Cookies without Validation and Integrity Checking in a Security Decision

<0:102.3.0-6.el7_9
  • H
Improper Handling of Inconsistent Structural Elements

<0:102.3.0-6.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.3.0-6.el7_9
  • H
Buffer Overflow

<0:102.8.0-2.el7_9
  • H
Buffer Overflow

<0:102.8.0-2.el7_9
  • H
Insufficient UI Warning of Dangerous Operations

<0:102.8.0-2.el7_9
  • H
Improper Handling of Alternate Encoding

<0:102.8.0-2.el7_9
  • H
Use After Free

<0:102.8.0-2.el7_9
  • H
Incorrect Type Conversion or Cast

<0:102.8.0-2.el7_9
  • H
Use After Free

<0:102.8.0-2.el7_9
  • H
Out-of-bounds Write

<0:102.8.0-2.el7_9
  • H
Incorrect Synchronization

<0:102.8.0-2.el7_9
  • H
Cross-site Scripting (XSS)

<0:102.8.0-2.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:102.8.0-2.el7_9
  • H
Heap-based Buffer Overflow

<0:102.15.1-1.el7_9
  • H
Heap-based Buffer Overflow

<0:102.15.1-1.el7_9
  • H
Out-of-Bounds

<0:115.3.1-1.el7_9
  • H
Buffer Overflow

<0:115.3.1-1.el7_9
  • H
Use After Free

<0:115.3.1-1.el7_9
  • H
Out-of-bounds Write

<0:115.3.1-1.el7_9
  • H
Use After Free

<0:115.3.1-1.el7_9
  • H
Buffer Overflow

<0:91.6.0-1.el7_9
  • H
Arbitrary Code Injection

<0:91.6.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.6.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.6.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.6.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.6.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.6.0-1.el7_9
  • H
Buffer Overflow

<0:102.12.0-1.el7_9
  • H
The UI Performs the Wrong Action

<0:102.12.0-1.el7_9
  • H
Buffer Overflow

<0:91.11.0-2.el7_9
  • H
Integer Overflow or Wraparound

<0:91.11.0-2.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.11.0-2.el7_9
  • H
Return of Wrong Status Code

<0:91.11.0-2.el7_9
  • H
Use After Free

<0:91.11.0-2.el7_9
  • H
Cross-site Scripting (XSS)

<0:91.11.0-2.el7_9
  • H
Cross-site Scripting (XSS)

<0:91.11.0-2.el7_9
  • H
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0:91.11.0-2.el7_9
  • H
Buffer Overflow

<0:102.9.0-3.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:102.9.0-3.el7_9
  • H
Incorrect Type Conversion or Cast

<0:102.9.0-3.el7_9
  • H
Out-of-bounds Read

<0:102.9.0-3.el7_9
  • H
Buffer Overflow

<0:91.9.0-1.el7_9
  • H
Arbitrary Code Injection

<0:102.9.0-3.el7_9
  • H
Exposure of System Data to an Unauthorized Control Sphere

<0:91.9.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.9.0-1.el7_9
  • H
Reliance on Cookies without Validation and Integrity Checking

<0:91.9.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.9.0-1.el7_9
  • H
Improper Preservation of Permissions

<0:91.9.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.12.0-2.el7_9
  • H
Cross-site Scripting (XSS)

<0:91.12.0-2.el7_9
  • H
Buffer Overflow

<0:91.12.0-2.el7_9
  • H
Buffer Overflow

<0:102.4.0-1.el7_9
  • H
Resource Exhaustion

<0:102.4.0-1.el7_9
  • H
Buffer Overflow

<0:102.4.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:102.4.0-1.el7_9
  • H
Buffer Overflow

<0:102.7.0-1.el7_9
  • H
Incorrect Regular Expression

<0:102.7.0-1.el7_9
  • H
CVE-2023-23602

<0:102.7.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:102.7.0-1.el7_9
  • H
Arbitrary Command Injection

<0:102.7.0-1.el7_9
  • H
Multiple Interpretations of UI Input

<0:102.7.0-1.el7_9
  • H
Insufficient UI Warning of Dangerous Operations

<0:102.7.0-1.el7_9
  • H
Use of Unmaintained Third Party Components

<0:102.7.0-1.el7_9
  • H
Buffer Overflow

<0:91.8.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.8.0-1.el7_9
  • H
Out-of-bounds Read

<0:91.8.0-1.el7_9
  • H
Use After Free

<0:91.8.0-1.el7_9
  • H
Out-of-bounds Write

<0:91.8.0-1.el7_9
  • H
Resource Exhaustion

<0:91.8.0-1.el7_9
  • H
Buffer Overflow

<0:115.11.0-1.el7_9
  • H
Use After Free

<0:91.8.0-1.el7_9
  • H
Use After Free

<0:115.11.0-1.el7_9
  • H
Use After Free

<0:91.8.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:115.11.0-1.el7_9
  • H
User Interface (UI) Misrepresentation of Critical Information

<0:115.11.0-1.el7_9
  • H
Improper Cross-boundary Removal of Sensitive Data

<0:115.11.0-1.el7_9
  • H
Improper Check for Unusual or Exceptional Conditions

<0:115.11.0-1.el7_9
  • H
Out-of-bounds Write

<0:78.12.0-1.el7_9
  • H
Buffer Overflow

<0:78.12.0-1.el7_9
  • H
Use After Free

<0:78.12.0-1.el7_9
  • C
Buffer Overflow

<0:78.8.0-1.el7_9
  • C
Information Exposure

<0:78.8.0-1.el7_9
  • C
Information Exposure

<0:78.8.0-1.el7_9
  • C
Information Exposure

<0:78.8.0-1.el7_9
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:91.9.1-1.el7_9
  • C
Access of Resource Using Incompatible Type ('Type Confusion')

<0:91.9.1-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.4.0-1.el7_9
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<0:91.4.0-1.el7_9
  • H
Cross-site Scripting (XSS)

<0:91.4.0-1.el7_9
  • H
Information Exposure

<0:91.4.0-1.el7_9
  • H
Unquoted Search Path or Element

<0:91.4.0-1.el7_9
  • H
Use After Free

<0:91.4.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.4.0-1.el7_9
  • H
Buffer Overflow

<0:91.4.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.4.0-1.el7_9
  • H
Buffer Overflow

<0:91.4.0-1.el7_9
  • H
Buffer Overflow

<0:115.10.0-1.el7_9
  • H
Use After Free

<0:115.10.0-1.el7_9
  • H
Integer Overflow or Wraparound

<0:115.10.0-1.el7_9
  • H
Use After Free

<0:115.10.0-1.el7_9
  • H
Out-of-bounds Read

<0:115.10.0-1.el7_9
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<0:115.10.0-1.el7_9
  • H
Resource Exhaustion

<0:115.10.0-1.el7_9
  • H
Product UI does not Warn User of Unsafe Actions

<0:115.10.0-1.el7_9
  • H
Use After Free

<0:91.3.0-1.el7_9
  • H
Buffer Overflow

<0:91.3.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.3.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.3.0-1.el7_9
  • H
Inclusion of Functionality from Untrusted Control Sphere

<0:91.3.0-1.el7_9
  • H
Improper Restriction of Rendered UI Layers or Frames

<0:91.3.0-1.el7_9
  • H
Use After Free

<0:91.3.0-1.el7_9
  • H
Incorrect Permission Assignment for Critical Resource

<0:91.3.0-1.el7_9
  • H
Buffer Overflow

<0:78.14.0-1.el7_9
  • H
Buffer Overflow

<0:115.7.0-1.el7_9
  • H
Inadequate Encryption Strength

<0:115.7.0-1.el7_9