Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 13 of 49
CVE-2019-9819P3CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9819 [CRITICAL] CWE-843 CVE-2019-9819: A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API,
A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2019-9820P3CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9820 [CRITICAL] CWE-416 CVE-2019-9820: A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in
A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2022-45406P3CRITICALCVSS 9.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45406 [CRITICAL] CWE-416 CVE-2022-45406: If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be
If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2021-4127P3CRITICALCVSS 9.8fixed in 78.9.0≥ unspecified, < 78.92022-12-22
CVE-2021-4127 [CRITICAL] CVE-2021-4127: An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be e
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird < 78.9 and Firefox ESR < 78.9.
nvd
CVE-2023-4057P3CRITICALCVSS 9.8fixed in 115.1≥ unspecified, < 115.12023-08-01
CVE-2023-4057 [CRITICAL] CWE-787 CVE-2023-4057: Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these b
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.
nvd
CVE-2022-31747P3CRITICALCVSS 9.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31747 [CRITICAL] CWE-125 CVE-2022-31747: Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memor
Mozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 and Firefox ESR 91.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thund
nvd
CVE-2017-7845P3HIGHCVSS 8.8≥ unspecified, < 52.5.22018-06-11
CVE-2017-7845 [HIGH] CWE-119 CVE-2017-7845: A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graph
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. Note: This attack only affects Windows operating systems. Other operating systems are unaf
nvd
CVE-2019-11745P3HIGHCVSS 8.8fixed in 68.3vbefore 68.32020-01-08
CVE-2019-11745 [HIGH] CWE-787 CVE-2019-11745: When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2022-26384P3CRITICALCVSS 9.6fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26384 [CRITICAL] CWE-693 CVE-2022-26384: If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but
If an attacker could control the contents of an iframe sandboxed with allow-popups but not allow-scripts, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvd
CVE-2024-7519P3CRITICALCVSS 9.6fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7519 [CRITICAL] CWE-787 CVE-2024-7519: Insufficient checks when processing graphics shared memory could have led to memory corruption. This
Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2018-5129P3HIGHCVSS 8.6≥ unspecified, < 52.72018-06-11
CVE-2018-5129 [HIGH] CWE-787 CVE-2018-5129: A lack of parameter validation on IPC messages results in a potential out-of-bounds write through ma
A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd
CVE-2026-74964P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74964 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74964
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74964
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-16369P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16369 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16369
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-16369
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-12295P3UNKNOWNfixed in Firefox ESR 115.37
CVE-2026-12295 Mozilla Foundation Security Advisory 2026-59: CVE-2026-12295
Mozilla Foundation Security Advisory 2026-59
CVE: CVE-2026-12295
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.37
mozilla
CVE-2026-12294P3UNKNOWNfixed in Firefox ESR 115.37
CVE-2026-12294 Mozilla Foundation Security Advisory 2026-59: CVE-2026-12294
Mozilla Foundation Security Advisory 2026-59
CVE: CVE-2026-12294
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.37
mozilla
CVE-2026-84141P3UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84141 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84141
Mozilla Foundation Security Advisory 2026-85
CVE: CVE-2026-84141
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.2
mozilla
CVE-2026-74969P3UNKNOWNfixed in Firefox ESR 115.39
CVE-2026-74969 Mozilla Foundation Security Advisory 2026-75: CVE-2026-74969
Mozilla Foundation Security Advisory 2026-75
CVE: CVE-2026-74969
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.39
mozilla
CVE-2026-74949P3UNKNOWNfixed in Firefox ESR 140.14
CVE-2026-74949 Mozilla Foundation Security Advisory 2026-76: CVE-2026-74949
Mozilla Foundation Security Advisory 2026-76
CVE: CVE-2026-74949
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.14
mozilla
CVE-2026-74942P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74942 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74942
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74942
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74937P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74937 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74937
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74937
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla