firefox vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the firefox package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Out-of-Bounds

<54.0+build3-0ubuntu0.17.04.1
  • M
CVE-2017-7775

<54.0+build3-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<54.0+build3-0ubuntu0.17.04.1
  • M
Out-of-bounds Read

<54.0+build3-0ubuntu0.17.04.1
  • M
Out-of-bounds Read

<54.0+build3-0ubuntu0.17.04.1
  • M
Out-of-bounds Read

<54.0+build3-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<54.0+build3-0ubuntu0.17.04.1
  • M
Information Exposure

<57.0+build4-0ubuntu0.17.04.5
  • L
Cross-site Scripting (XSS)

<57.0+build4-0ubuntu0.17.04.5
  • M
CVE-2017-5390

<52.0.1+build2-0ubuntu1
  • M
Use After Free

<52.0.1+build2-0ubuntu1
  • M
Integer Overflow or Wraparound

<52.0.1+build2-0ubuntu1
  • M
Improper Input Validation

<56.0+build6-0ubuntu0.17.04.1
  • M
Use After Free

<54.0+build3-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
CVE-2017-7835

<57.0+build4-0ubuntu0.17.04.5
  • M
Use After Free

<55.0.1+build2-0ubuntu0.17.04.2
  • M
CVE-2017-7789

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Out-of-bounds Read

<54.0+build3-0ubuntu0.17.04.1
  • M
Improper Input Validation

<53.0+build6-0ubuntu0.17.04.1
  • L
Information Exposure

<52.0.1+build2-0ubuntu1
  • M
Incorrect Permission Assignment for Critical Resource

<56.0+build6-0ubuntu0.17.04.1
  • L
Out-of-bounds Read

<52.0.1+build2-0ubuntu1
  • M
Out-of-bounds Write

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Use After Free

<54.0+build3-0ubuntu0.17.04.1
  • M
Improper Input Validation

<57.0+build4-0ubuntu0.17.04.5
  • M
Use After Free

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Use After Free

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Directory Traversal

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<56.0+build6-0ubuntu0.17.04.1
  • M
Use After Free

<54.0+build3-0ubuntu0.17.04.1
  • M
Arbitrary Code Injection

<55.0.1+build2-0ubuntu0.17.04.2
  • L
Improper Input Validation

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<53.0+build6-0ubuntu0.17.04.1
  • M
Information Exposure

<52.0.1+build2-0ubuntu1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Out-of-bounds Write

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<54.0+build3-0ubuntu0.17.04.1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Improper Input Validation

<53.0+build6-0ubuntu0.17.04.1
  • M
File and Directory Information Exposure

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<54.0+build3-0ubuntu0.17.04.1
  • M
Incorrect Permission Assignment for Critical Resource

<52.0.1+build2-0ubuntu1
  • M
Out-of-bounds Write

<53.0+build6-0ubuntu0.17.04.1
  • M
Use After Free

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<53.0+build6-0ubuntu0.17.04.1
  • M
CVE-2017-5455

<53.0+build6-0ubuntu0.17.04.1
  • M
Improper Input Validation

<52.0.1+build2-0ubuntu1
  • L
Improper Input Validation

<52.0.1+build2-0ubuntu1
  • M
Use After Free

<52.0.1+build2-0ubuntu1
  • L
Improper Input Validation

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • M
Use After Free

<54.0+build3-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<56.0+build6-0ubuntu0.17.04.1
  • L
Improper Input Validation

<57.0+build4-0ubuntu0.17.04.5
  • M
Incorrect Default Permissions

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Improper Input Validation

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Use After Free

<54.0+build3-0ubuntu0.17.04.1
  • M
Improper Input Validation

<57.0+build4-0ubuntu0.17.04.5
  • M
Use After Free

<54.0+build3-0ubuntu0.17.04.1
  • L
CVE-2017-5419

<52.0.1+build2-0ubuntu1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • M
Open Redirect

<52.0.1+build2-0ubuntu1
  • M
Out-of-bounds Read

<53.0+build6-0ubuntu0.17.04.1
  • M
Incorrect Permission Assignment for Critical Resource

<53.0+build6-0ubuntu0.17.04.1
  • M
Improper Validation of Array Index

<53.0+build6-0ubuntu0.17.04.1
  • M
Incorrect Calculation

<53.0+build6-0ubuntu0.17.04.1
  • M
Improper Privilege Management

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Arbitrary Code Injection

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • M
Error Handling

<52.0.1+build2-0ubuntu1
  • M
Out-of-bounds Read

<53.0+build6-0ubuntu0.17.04.1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<53.0+build6-0ubuntu0.17.04.1
  • M
Use After Free

<52.0.1+build2-0ubuntu1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • L
Improper Input Validation

<52.0.1+build2-0ubuntu1
  • M
Information Exposure

<53.0+build6-0ubuntu0.17.04.1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • L
Improper Initialization

<53.0+build6-0ubuntu0.17.04.1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<53.0+build6-0ubuntu0.17.04.1
  • M
Allocation of Resources Without Limits or Throttling

<52.0.1+build2-0ubuntu1
  • M
Use After Free

<53.0+build6-0ubuntu0.17.04.1
  • M
Information Exposure

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Out-of-bounds Read

<54.0+build3-0ubuntu0.17.04.1
  • L
CVE-2017-7820

<56.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Use After Free

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Use After Free

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Improper Input Validation

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Cross-site Scripting (XSS)

<56.0+build6-0ubuntu0.17.04.1
  • M
Improper Input Validation

<54.0+build3-0ubuntu0.17.04.1
  • M
Use After Free

<56.0+build6-0ubuntu0.17.04.1
  • M
Improper Input Validation

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Out-of-bounds Read

<56.0+build6-0ubuntu0.17.04.1
  • M
CVE-2017-5386

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<55.0.1+build2-0ubuntu0.17.04.2
  • M
NULL Pointer Dereference

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Information Exposure

<57.0.1+build2-0ubuntu0.17.04.1
  • L
Information Exposure

<57.0+build4-0ubuntu0.17.04.5
  • L
CVE-2017-7822

<56.0+build6-0ubuntu0.17.04.1
  • L
Cross-site Scripting (XSS)

<53.0+build6-0ubuntu0.17.04.1
  • M
Information Exposure

<52.0.1+build2-0ubuntu1
  • M
Information Exposure

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<53.0+build6-0ubuntu0.17.04.1
  • M
Improper Input Validation

<52.0.1+build2-0ubuntu1
  • M
Cross-site Scripting (XSS)

<52.0.1+build2-0ubuntu1
  • M
Information Exposure

<57.0.1+build2-0ubuntu0.17.04.1
  • M
Information Exposure

<52.0.1+build2-0ubuntu1
  • M
Cross-site Scripting (XSS)

<53.0+build6-0ubuntu0.17.04.1
  • L
Race Condition

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<56.0+build6-0ubuntu0.17.04.1
  • M
Information Exposure

<56.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<55.0.1+build2-0ubuntu0.17.04.2
  • M
CVE-2017-7830

<57.0+build4-0ubuntu0.17.04.5
  • M
Cross-site Scripting (XSS)

<57.0+build4-0ubuntu0.17.04.5
  • L
DEPRECATED: Use of Uninitialized Resource

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Improper Input Validation

<56.0+build6-0ubuntu0.17.04.1
  • M
Information Exposure

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Use After Free

<52.0.1+build2-0ubuntu1
  • M
CVE-2017-5391

<52.0.1+build2-0ubuntu1
  • M
Use After Free

<52.0.1+build2-0ubuntu1
  • M
Improper Input Validation

<56.0+build6-0ubuntu0.17.04.1
  • M
Information Exposure

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Out-of-Bounds

<54.0+build3-0ubuntu0.17.04.1
  • M
Improper Input Validation

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Improper Input Validation

<57.0+build4-0ubuntu0.17.04.5
  • L
Cross-site Scripting (XSS)

<57.0+build4-0ubuntu0.17.04.5
  • M
Out-of-bounds Read

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Out-of-Bounds

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Use After Free

<56.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<52.0.1+build2-0ubuntu1
  • M
Improper Input Validation

<54.0+build3-0ubuntu0.17.04.1
  • M
Use After Free

<56.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<57.0+build4-0ubuntu0.17.04.5
  • M
Use After Free

<52.0.1+build2-0ubuntu1
  • M
Information Exposure

<52.0.1+build2-0ubuntu1
  • M
Out-of-Bounds

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<57.0+build4-0ubuntu0.17.04.5
  • M
Use After Free

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Cross-site Scripting (XSS)

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Use After Free

<54.0+build3-0ubuntu0.17.04.1
  • M
Use After Free

<57.0+build4-0ubuntu0.17.04.5
  • M
Use After Free

<56.0+build6-0ubuntu0.17.04.1
  • M
CVE-2017-7781

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Origin Validation Error

<55.0.1+build2-0ubuntu0.17.04.2
  • M
Information Exposure

<57.0.4+build1-0ubuntu0.17.04.1
  • M
Information Exposure

<57.0.4+build1-0ubuntu0.17.04.1
  • M
Information Exposure

<57.0.4+build1-0ubuntu0.17.04.1
  • M
Out-of-bounds Write

<53.0+build6-0ubuntu0.17.04.1
  • L
Out-of-bounds Read

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-bounds Read

<53.0+build6-0ubuntu0.17.04.1
  • M
Out-of-Bounds

<53.0+build6-0ubuntu0.17.04.1
  • M
CVE-2016-2834

<47.0+build3-0ubuntu1
  • M
Cryptographic Issues

<44.0+build3-0ubuntu1
  • M
Improper Data Handling

<43.0.4+build3-0ubuntu1
  • M
Out-of-Bounds

<42.0+build2-0ubuntu1
  • M
Cryptographic Issues

<39.0+build5-0ubuntu1
  • M
Out-of-Bounds

<15.0+build1-0ubuntu1
  • M
Information Exposure

<12.0+build1-0ubuntu0.12.04.1