cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 12 of 45
CVE-2021-4127P3CRITICALCVSS 9.8fixed in 78.9.0≥ unspecified, < 78.92022-12-22
CVE-2021-4127 [CRITICAL] CVE-2021-4127: An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be e An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
nvd
CVE-2022-31747P3CRITICALCVSS 9.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31747 [CRITICAL] CWE-125 CVE-2022-31747: Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memor Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thund
nvd
CVE-2023-4057P3CRITICALCVSS 9.8fixed in 115.1≥ unspecified, < 115.12023-08-01
CVE-2023-4057 [CRITICAL] CWE-787 CVE-2023-4057: Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these b Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.
nvd
CVE-2017-7845P3HIGHCVSS 8.8≥ unspecified, < 52.5.22018-06-11
CVE-2017-7845 [HIGH] CWE-119 CVE-2017-7845: A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graph A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This attack only affects Windows operating systems. Other operating systems are unaf
nvd
CVE-2022-26384P3CRITICALCVSS 9.6fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26384 [CRITICAL] CWE-693 CVE-2022-26384: If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvd
CVE-2024-7519P3CRITICALCVSS 9.6fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7519 [CRITICAL] CWE-787 CVE-2024-7519: Insufficient checks when processing graphics shared memory could have led to memory corruption. This Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2020-15659P3HIGHCVSS 8.8fixed in 68.11≥ 78.0, < 78.1.0+2 more2020-08-10
CVE-2020-15659 [HIGH] CWE-787 CVE-2020-15659: Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1,
nvd
CVE-2026-12295P3UNKNOWNfixed in Firefox ESR 115.37
CVE-2026-12295 Mozilla Foundation Security Advisory 2026-59: CVE-2026-12295 Mozilla Foundation Security Advisory 2026-59 CVE: CVE-2026-12295 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.37
mozilla
CVE-2026-12294P3UNKNOWNfixed in Firefox ESR 115.37
CVE-2026-12294 Mozilla Foundation Security Advisory 2026-59: CVE-2026-12294 Mozilla Foundation Security Advisory 2026-59 CVE: CVE-2026-12294 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.37
mozilla
CVE-2026-7321P3UNKNOWNfixed in Firefox ESR 140.10.1
CVE-2026-7321 Mozilla Foundation Security Advisory 2026-36: CVE-2026-7321 Mozilla Foundation Security Advisory 2026-36 CVE: CVE-2026-7321 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10.1
mozilla
CVE-2026-16396P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16396 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16396 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16396 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2020-15673P3HIGHCVSS 8.8fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15673 [HIGH] CWE-416 CVE-2020-15673: Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of t Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2021-23994P3HIGHCVSS 8.8fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-23994 [HIGH] CWE-909 CVE-2021-23994: A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of b A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2020-26960P3HIGHCVSS 8.8fixed in 78.52020-12-09
CVE-2020-26960 [HIGH] CWE-416 CVE-2020-26960: If the Compact() method was called on an nsTArray, the array could have been reallocated without upd If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2020-26973P3HIGHCVSS 8.8fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-26973 [HIGH] CVE-2020-26973: Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. Thi Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2020-6799P3HIGHCVSS 8.8fixed in 68.5.02020-03-02
CVE-2020-6799 [HIGH] CWE-88 CVE-2020-6799: Command line arguments could have been injected during Firefox invocation as a shell handler for cer Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded to be opened in a third party application that insufficiently sanitized URL data. In that situation, clicking a link
nvd
CVE-2021-23987P3HIGHCVSS 8.8fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23987 [HIGH] CWE-787 CVE-2021-23987: Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.
nvd
CVE-2021-29989P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.132021-08-17
CVE-2021-29989 [HIGH] CWE-787 CVE-2021-29989: Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.13, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2021-29976P3HIGHCVSS 8.8fixed in 78.12≥ unspecified, < 78.122021-08-05
CVE-2021-29976 [HIGH] CWE-787 CVE-2021-29976: Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbir Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
nvd
CVE-2021-38493P3HIGHCVSS 8.8fixed in 78.14≥ unspecified, < 78.142021-11-03
CVE-2021-38493 [HIGH] CWE-787 CVE-2021-38493: Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase