cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 11 of 45
CVE-2022-45409P3HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45409 [HIGH] CWE-416 CVE-2022-45409: The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finis The garbage collector could have been aborted in several states and zones and GCRuntime::finishCollection may not have been called, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2023-37201P3HIGHCVSS 8.8fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37201 [HIGH] CWE-416 CVE-2023-37201: An attacker could have triggered a use-after-free condition when creating a WebRTC connection over H An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2023-37211P3HIGHCVSS 8.8fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37211 [HIGH] CWE-787 CVE-2023-37211: Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2024-0755P3HIGHCVSS 8.8fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0755 [HIGH] CWE-94 CVE-2024-0755: Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these b Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2023-32207P3HIGHCVSS 8.8fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32207 [HIGH] CWE-290 CVE-2023-32207: A missing delay in popup notifications could have made it possible for an attacker to trick a user i A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2022-31739P3HIGHCVSS 8.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31739 [HIGH] CWE-73 CVE-2022-31739: When downloading files on Windows, the % character was not escaped, which could have lead to a downl When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 91.10, Firefox < 1
nvd
CVE-2024-4777P3HIGHCVSS 8.8≥ unspecified, < 115.112024-05-14
CVE-2024-4777 [HIGH] CWE-787 CVE-2024-4777: Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2024-7528P3HIGHCVSS 8.8fixed in 128.1.0≥ unspecified, < 128.12024-08-06
CVE-2024-7528 [HIGH] CWE-416 CVE-2024-7528: Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulne Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
nvd
CVE-2018-5156P3CRITICALCVSS 9.8≥ unspecified, < 60.1≥ unspecified, < 52.92018-10-18
CVE-2018-5156 [CRITICAL] CWE-20 CVE-2018-5156: A vulnerability can occur when capturing a media stream when the media source type is changed as the A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2014-1567P3CRITICALCVSS 9.3v24.2v24.3+4 more2014-09-03
CVE-2014-1567 [CRITICAL] CVE-2014-1567: Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.
nvd
CVE-2023-4576P3HIGHCVSS 8.6fixed in 102.15≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4576 [HIGH] CWE-190 CVE-2023-4576: On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a h On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR
nvd
CVE-2017-5460P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5460 [CRITICAL] CWE-416 CVE-2017-5460: A use-after-free vulnerability in frame selection triggered by a combination of malicious script con A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2024-1553P3HIGHCVSS 8.1≥ unspecified, < 115.82024-02-20
CVE-2024-1553 [HIGH] CWE-119 CVE-2024-1553: Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these b Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2026-6785P3HIGHCVSS 8.1fixed in Firefox ESR 140.10
CVE-2026-6785 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6785 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6785 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2019-9796P3CRITICALCVSS 9.8≥ unspecified, < 60.62019-04-26
CVE-2019-9796 [CRITICAL] CWE-416 CVE-2019-9796: A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers wi A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the driver's observer array.
nvd
CVE-2019-9790P3CRITICALCVSS 9.8≥ unspecified, < 60.62019-04-26
CVE-2019-9790 [CRITICAL] CWE-416 CVE-2019-9790: A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained u A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvd
CVE-2019-9795P3CRITICALCVSS 9.8fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9795 [CRITICAL] CWE-617 CVE-2019-9795: A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvd
CVE-2019-9819P3CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9819 [CRITICAL] CWE-843 CVE-2019-9819: A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2019-9820P3CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9820 [CRITICAL] CWE-416 CVE-2019-9820: A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2022-45406P3CRITICALCVSS 9.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45406 [CRITICAL] CWE-416 CVE-2022-45406: If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase