Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 15 of 49
CVE-2024-9396P3HIGHCVSS 8.8≥ unspecified, < 128.32024-10-01
CVE-2024-9396 [HIGH] CWE-119 CVE-2024-9396: It is currently unknown if this issue is exploitable but a condition may arise where the structured
It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2024-9400P3HIGHCVSS 8.8≥ unspecified, < 128.32024-10-01
CVE-2024-9400 [HIGH] CWE-119 CVE-2024-9400: A potential memory corruption vulnerability could be triggered if an attacker had the ability to tri
A potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during JIT compilation. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2018-5188P3CRITICALCVSS 9.8fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-5188 [CRITICAL] CWE-119 CVE-2018-5188: Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs s
Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefo
nvd
CVE-2017-5455P3HIGHCVSS 7.5≥ unspecified, < 52.12018-06-11
CVE-2017-5455 [HIGH] CVE-2017-5455: The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and esca
The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vulnerability that resulted in remote code execution inside the sandboxed process. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
nvd
CVE-2017-7824P3CRITICALCVSS 9.8≥ unspecified, < 52.42018-06-11
CVE-2017-7824 [CRITICAL] CWE-119 CVE-2017-7824: A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2017-5433P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5433 [CRITICAL] CWE-416 CVE-2017-5433: A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation element
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5434P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5434 [CRITICAL] CWE-416 CVE-2017-5434: A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially
A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5439P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5439 [CRITICAL] CWE-416 CVE-2017-5439: A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. T
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-7784P3CRITICALCVSS 9.8fixed in 52.32018-06-11
CVE-2017-7784 [CRITICAL] CWE-416 CVE-2017-7784: A use-after-free vulnerability can occur when reading an image observer during frame reconstruction
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2016-9898P3CRITICALCVSS 9.8≥ unspecified, < 45.62018-06-11
CVE-2016-9898 [CRITICAL] CWE-416 CVE-2016-9898: Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Edit
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-7818P3CRITICALCVSS 9.8≥ unspecified, < 52.42018-06-11
CVE-2017-7818 [CRITICAL] CWE-416 CVE-2017-7818: A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applic
A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containers through the DOM. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2018-5091P3CRITICALCVSS 9.8≥ unspecified, < 52.62018-06-11
CVE-2018-5091 [CRITICAL] CWE-416 CVE-2018-5091: A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF ti
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.
nvd
CVE-2017-5443P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5443 [CRITICAL] CWE-787 CVE-2017-5443: An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This v
An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2020-15683P3CRITICALCVSS 9.8fixed in 78.4≥ unspecified, < 78.42020-10-22
CVE-2020-15683 [CRITICAL] CWE-416 CVE-2020-15683: Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.4, Firefox < 82, and Thunderbird <
nvd
CVE-2014-1556P3CRITICALCVSS 9.3v24.2v24.3+3 more2014-07-23
CVE-2014-1556 [CRITICAL] CWE-94 CVE-2014-1556: Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote
Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to execute arbitrary code via crafted WebGL content constructed with the Cesium JavaScript library.
nvd
CVE-2026-6786P3HIGHCVSS 8.1fixed in Firefox ESR 140.10
CVE-2026-6786 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6786
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6786
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2018-12359P3HIGHCVSS 8.8fixed in 52.9≥ 53.0, < 60.1+2 more2018-10-18
CVE-2018-12359 [HIGH] CWE-119 CVE-2018-12359: A buffer overflow can occur when rendering canvas content while adjusting the height and width of th
A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written outside of the currently computed boundaries. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52
nvd
CVE-2019-9790P3CRITICALCVSS 9.8≥ unspecified, < 60.62019-04-26
CVE-2019-9790 [CRITICAL] CWE-416 CVE-2019-9790: A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained u
A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvd
CVE-2015-2716P3HIGHCVSS 7.5v31.1v31.2+4 more2015-05-14
CVE-2015-2716 [HIGH] CVE-2015-2716: Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
nvd
CVE-2018-5178P3HIGHCVSS 8.1≥ unspecified, < 52.82018-06-11
CVE-2018-5178 [HIGH] CWE-119 CVE-2018-5178: A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremel
A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerability requires the use of a malicious or vulnerable legacy extension in order to occur. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
nvd