cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 14 of 45
CVE-2026-6786P3HIGHCVSS 8.1fixed in Firefox ESR 140.10
CVE-2026-6786 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6786 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6786 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2018-12359P3HIGHCVSS 8.8fixed in 52.9≥ 53.0, < 60.1+2 more2018-10-18
CVE-2018-12359 [HIGH] CWE-119 CVE-2018-12359: A buffer overflow can occur when rendering canvas content while adjusting the height and width of th A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written outside of the currently computed boundaries. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52
nvd
CVE-2015-2716P3HIGHCVSS 7.5v31.1v31.2+4 more2015-05-14
CVE-2015-2716 [HIGH] CVE-2015-2716: Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
nvd
CVE-2018-5178P3HIGHCVSS 8.1≥ unspecified, < 52.82018-06-11
CVE-2018-5178 [HIGH] CWE-119 CVE-2018-5178: A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremel A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
nvd
CVE-2019-11745P3HIGHCVSS 8.8fixed in 68.3vbefore 68.32020-01-08
CVE-2019-11745 [HIGH] CWE-787 CVE-2019-11745: When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2018-5129P3HIGHCVSS 8.6≥ unspecified, < 52.72018-06-11
CVE-2018-5129 [HIGH] CWE-787 CVE-2018-5129: A lack of parameter validation on IPC messages results in a potential out-of-bounds write through ma A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd
CVE-2026-12291P3UNKNOWNfixed in Firefox ESR 140.12
CVE-2026-12291 Mozilla Foundation Security Advisory 2026-58: CVE-2026-12291 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12291 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-16379P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16379 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16379 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16379 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2018-12391P3HIGHCVSS 8.8fixed in 60.3≥ unspecified, < 60.32019-02-28
CVE-2018-12391 [HIGH] CWE-863 CVE-2018-12391: During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins i During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of
nvd
CVE-2019-17008P3HIGHCVSS 8.8fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17008 [HIGH] CWE-416 CVE-2019-17008: When using nested workers, a use-after-free could occur during worker destruction. This resulted in When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2021-43539P3HIGHCVSS 8.8fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43539 [HIGH] CWE-416 CVE-2021-43539: Failure to correctly record the location of live pointers across wasm instance calls resulted in a G Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-23978P3HIGHCVSS 8.8fixed in 78.82021-02-26
CVE-2021-23978 [HIGH] CWE-787 CVE-2021-23978: Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of t Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2020-15656P3HIGHCVSS 8.8fixed in 78.1≥ unspecified, < 78.12020-08-10
CVE-2020-15656 [HIGH] CWE-843 CVE-2020-15656: JIT optimizations involving the Javascript arguments object could confuse later optimizations. This JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2020-26968P3HIGHCVSS 8.8fixed in 78.52020-12-09
CVE-2020-26968 [HIGH] CWE-787 CVE-2020-26968: Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of t Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2020-26974P3HIGHCVSS 8.8fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-26974 [HIGH] CWE-787 CVE-2020-26974: When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrec When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2020-35113P3HIGHCVSS 8.8fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-35113 [HIGH] CWE-787 CVE-2020-35113: Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of t Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2021-23999P3HIGHCVSS 8.8fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-23999 [HIGH] CWE-269 CVE-2021-23999: If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the Sys If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2021-23964P3HIGHCVSS 8.8fixed in 78.72021-02-26
CVE-2021-23964 [HIGH] CWE-787 CVE-2021-23964: Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of t Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvd
CVE-2021-38500P3HIGHCVSS 8.8fixed in 78.15≥ unspecified, < 91.2+1 more2021-11-03
CVE-2021-38500 [HIGH] CVE-2021-38500: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and
nvd
CVE-2021-43534P3HIGHCVSS 8.8fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-43534 [HIGH] CWE-787 CVE-2021-43534: Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase