Mozilla Firefox Esr vulnerabilities
776 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
776
CISA KEV
9
actively exploited
Public exploits
17
Exploited in wild
13
Severity breakdown
CRITICAL186HIGH315MEDIUM269LOW6
Vulnerabilities
Page 10 of 39
CVE-2023-25746HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25746 [HIGH] CWE-787 CVE-2023-25746: Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corrup
Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.8 and Firefox ESR < 102.8.
cvelistv5nvd
CVE-2023-25732HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25732 [HIGH] CWE-787 CVE-2023-25732: When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input bein
When encoding data from an inputStream in xpcom the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
cvelistv5nvd
CVE-2023-25744HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25744 [HIGH] CWE-787 CVE-2023-25744: Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence
Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
cvelistv5nvd
CVE-2023-28176HIGHCVSS 8.8fixed in 102.9≥ unspecified, < 102.92023-06-02
CVE-2023-28176 [HIGH] CWE-787 CVE-2023-28176: Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
cvelistv5nvd
CVE-2023-25735HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25735 [HIGH] CWE-416 CVE-2023-25735: Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartmen
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
cvelistv5nvd
CVE-2023-25737HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25737 [HIGH] CWE-704 CVE-2023-25737: An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undef
An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
cvelistv5nvd
CVE-2023-28162HIGHCVSS 8.8fixed in 102.9≥ unspecified, < 102.92023-06-02
CVE-2023-28162 [HIGH] CWE-704 CVE-2023-28162: While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic ty
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
cvelistv5nvd
CVE-2023-25734HIGHCVSS 8.1fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25734 [HIGH] CWE-601 CVE-2023-25734: After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could
After downloading a Windows .url shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability
cvelistv5nvd
CVE-2023-29541HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29541 [HIGH] CWE-116 CVE-2023-29541: Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be int
Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112,
cvelistv5nvd
CVE-2023-25743HIGHCVSS 7.5≥ unspecified, < 102.82023-06-02
CVE-2023-25743 [HIGH] CWE-290 CVE-2023-25743: A lack of in app notification for entering fullscreen mode could have lead to a malicious website sp
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
cvelistv5nvd
CVE-2023-25729HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25729 [HIGH] CWE-863 CVE-2023-25729: Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> r
Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox <
cvelistv5nvd
CVE-2023-29550HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29550 [HIGH] CVE-2023-29550: Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence
Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.1
cvelistv5nvd
CVE-2023-23605HIGHCVSS 8.8fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23605 [HIGH] CWE-787 CVE-2023-23605: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 a
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunde
cvelistv5nvd
CVE-2023-25739HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25739 [HIGH] CWE-416 CVE-2023-25739: Module load requests that failed were not being checked as to whether or not they were cancelled cau
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in ScriptLoadContext. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
cvelistv5nvd
CVE-2023-32207HIGHCVSS 8.8fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32207 [HIGH] CWE-290 CVE-2023-32207: A missing delay in popup notifications could have made it possible for an attacker to trick a user i
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
cvelistv5nvd
CVE-2023-29539HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29539 [HIGH] CWE-476 CVE-2023-29539: When handling the filename directive in the Content-Disposition header, the filename would be trunca
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for An
cvelistv5nvd
CVE-2023-0767HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-0767 [HIGH] CVE-2023-0767: An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memor
An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
cvelistv5nvd
CVE-2023-25738MEDIUMCVSS 6.5fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25738 [MEDIUM] CWE-125 CVE-2023-25738: Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated
Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thu
cvelistv5nvd
CVE-2023-23599MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23599 [MEDIUM] CWE-116 CVE-2023-23599: When copying a network request from the developer tools panel as a curl command the output was not b
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
cvelistv5nvd
CVE-2023-23598MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23598 [MEDIUM] CVE-2023-23598: Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plai
Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
cvelistv5nvd