Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 10 of 45
CVE-2026-12297P3UNKNOWNfixed in Firefox ESR 140.12
CVE-2026-12297 Mozilla Foundation Security Advisory 2026-58: CVE-2026-12297
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12297
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-8092P3UNKNOWNfixed in Firefox ESR 115.35.2
CVE-2026-8092 Mozilla Foundation Security Advisory 2026-42: CVE-2026-8092
Mozilla Foundation Security Advisory 2026-42
CVE: CVE-2026-8092
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35.2
mozilla
CVE-2026-16362P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16362 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16362
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-16362
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16371P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16371 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16371
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-16371
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
mozilla
CVE-2017-7798P3HIGHCVSS 8.8≥ unspecified, < 52.32018-06-11
CVE-2017-7798 [HIGH] CWE-94 CVE-2017-7798: The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization
The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the style editor tool. This vulnerability affects Firefox ESR < 52.3 and Firefox < 55.
nvd
CVE-2021-43537P3HIGHCVSS 8.8fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43537 [HIGH] CWE-704 CVE-2021-43537: An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt me
An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-15678P3HIGHCVSS 8.8fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15678 [HIGH] CWE-416 CVE-2020-15678: When recursing through graphical layers while scrolling, an iterator may have become invalid, result
When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did not follow iterator invalidation rules. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2020-26971P3HIGHCVSS 8.8fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-26971 [HIGH] CWE-787 CVE-2020-26971: Certain blit values provided by the user were not properly constrained leading to a heap buffer over
Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2014-1551P3CRITICALCVSS 10.0v24.2v24.3+3 more2014-07-23
CVE-2014-1551 [CRITICAL] CVE-2014-1551: Use-after-free vulnerability in the FontTableRec destructor in Mozilla Firefox before 31.0, Firefox
Use-after-free vulnerability in the FontTableRec destructor in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 on Windows allows remote attackers to execute arbitrary code via crafted use of fonts in MathML content, leading to improper handling of a DirectWrite font-face object.
nvd
CVE-2023-6858P3HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6858 [HIGH] CWE-787 CVE-2023-6858: Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handli
Firefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2022-40962P3HIGHCVSS 8.8fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40962 [HIGH] CWE-787 CVE-2022-40962: Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla
Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 104 and Firefox ESR 102.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vuln
nvd
CVE-2021-23995P3HIGHCVSS 8.8fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-23995 [HIGH] CWE-672 CVE-2021-23995: When Responsive Design Mode was enabled, it used references to objects that were previously freed. W
When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2023-6864P3HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6864 [HIGH] CWE-787 CVE-2023-6864: Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these b
Memory safety bugs present in Firefox 120, Firefox ESR 115.5, and Thunderbird 115.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2017-5459P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5459 [CRITICAL] CWE-119 CVE-2017-5459: A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash.
A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2021-38510P3HIGHCVSS 8.8fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38510 [HIGH] CVE-2021-38510: The executable file warning was not presented when downloading .inetloc files, which, due to a flaw
The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2022-22740P3HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22740 [HIGH] CWE-416 CVE-2022-22740: Certain network request objects were freed too early when releasing a network request handle. This c
Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-6862P3HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6862 [HIGH] CWE-416 CVE-2023-6862: A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely
A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affects Firefox ESR < 115.6 and Thunderbird < 115.6.
nvd
CVE-2022-38478P3HIGHCVSS 8.8fixed in 91.13≥ unspecified, < 91.13+1 more2022-12-22
CVE-2022-38478 [HIGH] CWE-787 CVE-2022-38478: Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102
Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13,
nvd
CVE-2022-26381P3HIGHCVSS 8.8fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26381 [HIGH] CWE-416 CVE-2022-26381: An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to
An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvd
CVE-2023-6212P3HIGHCVSS 8.8fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6212 [HIGH] CWE-787 CVE-2023-6212: Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these b
Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd