Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 14 of 49
CVE-2026-7321P3UNKNOWNfixed in Firefox ESR 140.10.1
CVE-2026-7321 Mozilla Foundation Security Advisory 2026-36: CVE-2026-7321
Mozilla Foundation Security Advisory 2026-36
CVE: CVE-2026-7321
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10.1
mozilla
CVE-2021-23994P3HIGHCVSS 8.8fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-23994 [HIGH] CWE-909 CVE-2021-23994: A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of b
A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2021-43539P3HIGHCVSS 8.8fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43539 [HIGH] CWE-416 CVE-2021-43539: Failure to correctly record the location of live pointers across wasm instance calls resulted in a G
Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-26973P3HIGHCVSS 8.8fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-26973 [HIGH] CVE-2020-26973: Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. Thi
Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2020-26960P3HIGHCVSS 8.8fixed in 78.52020-12-09
CVE-2020-26960 [HIGH] CWE-416 CVE-2020-26960: If the Compact() method was called on an nsTArray, the array could have been reallocated without upd
If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2020-35113P3HIGHCVSS 8.8fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-35113 [HIGH] CWE-787 CVE-2020-35113: Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of t
Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2020-6799P3HIGHCVSS 8.8fixed in 68.5.02020-03-02
CVE-2020-6799 [HIGH] CWE-88 CVE-2020-6799: Command line arguments could have been injected during Firefox invocation as a shell handler for cer
Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This required Firefox to be configured as the default handler for a given file type and for a file downloaded to be opened in a third party application that insufficiently sanitized URL data. In that situation, clicking a link
nvd
CVE-2020-26974P3HIGHCVSS 8.8fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-26974 [HIGH] CWE-787 CVE-2020-26974: When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrec
When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2021-23987P3HIGHCVSS 8.8fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23987 [HIGH] CWE-787 CVE-2021-23987: Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.
nvd
CVE-2021-38500P3HIGHCVSS 8.8fixed in 78.15≥ unspecified, < 91.2+1 more2021-11-03
CVE-2021-38500 [HIGH] CVE-2021-38500: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and
nvd
CVE-2021-29989P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.132021-08-17
CVE-2021-29989 [HIGH] CWE-787 CVE-2021-29989: Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of
Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.13, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2021-38493P3HIGHCVSS 8.8fixed in 78.14≥ unspecified, < 78.142021-11-03
CVE-2021-38493 [HIGH] CWE-787 CVE-2021-38493: Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of
Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.14, Thunderbird < 78.14, and Firefox < 92.
nvd
CVE-2021-29976P3HIGHCVSS 8.8fixed in 78.12≥ unspecified, < 78.122021-08-05
CVE-2021-29976 [HIGH] CWE-787 CVE-2021-29976: Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbir
Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
nvd
CVE-2023-6863P3HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6863 [HIGH] CVE-2023-6863: The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a
The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2022-46874P3HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46874 [HIGH] CWE-94 CVE-2022-46874: A file with a long filename could have had its filename truncated to remove the valid extension, lea
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitte
nvd
CVE-2023-6212P3HIGHCVSS 8.8fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6212 [HIGH] CWE-787 CVE-2023-6212: Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these b
Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2023-32207P3HIGHCVSS 8.8fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32207 [HIGH] CWE-290 CVE-2023-32207: A missing delay in popup notifications could have made it possible for an attacker to trick a user i
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2023-23605P3HIGHCVSS 8.8fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23605 [HIGH] CWE-787 CVE-2023-23605: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 a
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunde
nvd
CVE-2023-29550P3HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29550 [HIGH] CVE-2023-29550: Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence
Memory safety bugs present in Firefox 111 and Firefox ESR 102.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.1
nvd
CVE-2023-28162P3HIGHCVSS 8.8fixed in 102.9≥ unspecified, < 102.92023-06-02
CVE-2023-28162 [HIGH] CWE-704 CVE-2023-28162: While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic ty
While implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd