Mozilla Firefox Esr vulnerabilities

776 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
776
CISA KEV
9
actively exploited
Public exploits
18
Exploited in wild
13
Severity breakdown
CRITICAL186HIGH315MEDIUM269LOW6

Vulnerabilities

Page 14 of 39
CVE-2022-22737HIGHCVSS 7.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22737 [HIGH] CWE-362 CVE-2022-22737: Constructing audio sinks could have lead to a race condition when playing audio files and closing wi Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
cvelistv5nvd
CVE-2022-2505HIGHCVSS 8.8fixed in 102.1≥ unspecified, < 102.12022-12-22
CVE-2022-2505 [HIGH] CWE-787 CVE-2022-2505: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
cvelistv5nvd
CVE-2022-38477HIGHCVSS 8.8fixed in 102.2≥ unspecified, < 102.22022-12-22
CVE-2022-38477 [HIGH] CWE-787 CVE-2022-38477: Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in F Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.2, Thunderbird <
cvelistv5nvd
CVE-2022-22753HIGHCVSS 7.1fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22753 [HIGH] CWE-367 CVE-2022-22753: A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6,
cvelistv5nvd
CVE-2022-38478HIGHCVSS 8.8fixed in 91.13≥ unspecified, < 91.13+1 more2022-12-22
CVE-2022-38478 [HIGH] CWE-787 CVE-2022-38478: Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102 Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13,
cvelistv5nvd
CVE-2022-22738HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22738 [HIGH] CWE-787 CVE-2022-22738: Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a hea Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
cvelistv5nvd
CVE-2022-46878HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46878 [HIGH] CWE-787 CVE-2022-46878: Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firef
cvelistv5nvd
CVE-2022-40962HIGHCVSS 8.8fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40962 [HIGH] CWE-787 CVE-2022-40962: Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Mozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 104 and Firefox ESR 102.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vuln
cvelistv5nvd
CVE-2022-42932HIGHCVSS 8.8fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42932 [HIGH] CWE-787 CVE-2022-42932: Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in F Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106, Firefox ESR < 102.4
cvelistv5nvd
CVE-2022-46881HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46881 [HIGH] CWE-787 CVE-2022-46881: An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106, Firefox ESR <
cvelistv5nvd
CVE-2022-45409HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45409 [HIGH] CWE-416 CVE-2022-45409: The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finis The garbage collector could have been aborted in several states and zones and GCRuntime::finishCollection may not have been called, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
cvelistv5nvd
CVE-2022-38473HIGHCVSS 8.8fixed in 91.13≥ unspecified, < 91.13+1 more2022-12-22
CVE-2022-38473 [HIGH] CWE-281 CVE-2022-38473: A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (su A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
cvelistv5nvd
CVE-2022-45421HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45421 [HIGH] CWE-787 CVE-2022-45421: Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thund Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox
cvelistv5nvd
CVE-2022-22744HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22744 [HIGH] CWE-116 CVE-2022-22744: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped fo The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunder
cvelistv5nvd
CVE-2022-22761HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22761 [HIGH] CWE-693 CVE-2022-22761: Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing t Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
cvelistv5nvd
CVE-2022-46874HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46874 [HIGH] CWE-94 CVE-2022-46874: A file with a long filename could have had its filename truncated to remove the valid extension, lea A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitte
cvelistv5nvd
CVE-2022-29912MEDIUMCVSS 6.1fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29912 [MEDIUM] CWE-601 CVE-2022-29912: Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
cvelistv5nvd
CVE-2022-40956MEDIUMCVSS 6.1fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40956 [MEDIUM] CWE-79 CVE-2022-40956: When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and acce When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
cvelistv5nvd
CVE-2022-22745MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22745 [MEDIUM] CWE-200 CVE-2022-22745: Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violat Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
cvelistv5nvd
CVE-2022-45410MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45410 [MEDIUM] CWE-862 CVE-2022-45410: When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request w When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
cvelistv5nvd