cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 12 of 49
CVE-2023-37201P3HIGHCVSS 8.8fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37201 [HIGH] CWE-416 CVE-2023-37201: An attacker could have triggered a use-after-free condition when creating a WebRTC connection over H An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2023-37211P3HIGHCVSS 8.8fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37211 [HIGH] CWE-787 CVE-2023-37211: Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2024-0755P3HIGHCVSS 8.8fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0755 [HIGH] CWE-94 CVE-2024-0755: Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these b Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2023-25729P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25729 [HIGH] CWE-863 CVE-2023-25729: Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> r Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox <
nvd
CVE-2022-31739P3HIGHCVSS 8.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31739 [HIGH] CWE-73 CVE-2022-31739: When downloading files on Windows, the % character was not escaped, which could have lead to a downl When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 91.10, Firefox < 1
nvd
CVE-2023-3600P3HIGHCVSS 8.8fixed in 115.0.2≥ unspecified, < 115.0.22023-07-12
CVE-2023-3600 [HIGH] CWE-416 CVE-2023-3600: During the worker lifecycle, a use-after-free condition could have occurred, which could have led to During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.
nvd
CVE-2024-4777P3HIGHCVSS 8.8≥ unspecified, < 115.112024-05-14
CVE-2024-4777 [HIGH] CWE-787 CVE-2024-4777: Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these Memory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2024-7528P3HIGHCVSS 8.8fixed in 128.1.0≥ unspecified, < 128.12024-08-06
CVE-2024-7528 [HIGH] CWE-416 CVE-2024-7528: Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulne Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
nvd
CVE-2023-4576P3HIGHCVSS 8.6fixed in 102.15≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4576 [HIGH] CWE-190 CVE-2023-4576: On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a h On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR
nvd
CVE-2018-5156P3CRITICALCVSS 9.8≥ unspecified, < 60.1≥ unspecified, < 52.92018-10-18
CVE-2018-5156 [CRITICAL] CWE-20 CVE-2018-5156: A vulnerability can occur when capturing a media stream when the media source type is changed as the A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result in stream data being cast to the wrong type causing a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2026-74952P3HIGHCVSS 8.8fixed in Firefox ESR 153.2
CVE-2026-74952 [HIGH] Mozilla Foundation Security Advisory 2026-85: CVE-2026-74952 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-74952 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2014-1567P3CRITICALCVSS 9.3v24.2v24.3+4 more2014-09-03
CVE-2014-1567 [CRITICAL] CVE-2014-1567: Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR Use-after-free vulnerability in DirectionalityUtils.cpp in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to execute arbitrary code via text that is improperly handled during the interaction between directionality resolution and layout.
nvd
CVE-2017-5438P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5438 [CRITICAL] CWE-416 CVE-2017-5438: A use-after-free vulnerability during XSLT processing due to the result handler being held by a free A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2018-12392P3CRITICALCVSS 9.8≥ unspecified, < 60.32019-02-28
CVE-2018-12392 [CRITICAL] CVE-2018-12392: When manipulating user events in nested loops while opening a document through script, it is possibl When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
nvd
CVE-2017-5460P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5460 [CRITICAL] CWE-416 CVE-2017-5460: A use-after-free vulnerability in frame selection triggered by a combination of malicious script con A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2024-1553P3HIGHCVSS 8.1≥ unspecified, < 115.82024-02-20
CVE-2024-1553 [HIGH] CWE-119 CVE-2024-1553: Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these b Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2024-3864P3HIGHCVSS 8.1≥ unspecified, < 115.102024-04-16
CVE-2024-3864 [HIGH] CWE-119 CVE-2024-3864: Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2026-6785P3HIGHCVSS 8.1fixed in Firefox ESR 140.10
CVE-2026-6785 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6785 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6785 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2019-9796P3CRITICALCVSS 9.8≥ unspecified, < 60.62019-04-26
CVE-2019-9796 [CRITICAL] CWE-416 CVE-2019-9796: A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers wi A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controller element, the refresh driver incorrectly leaves a dangling pointer to the driver's observer array.
nvd
CVE-2019-9795P3CRITICALCVSS 9.8fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9795 [CRITICAL] CWE-617 CVE-2019-9795: A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase