cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 16 of 49
CVE-2018-12363P3HIGHCVSS 8.8fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12363 [HIGH] CWE-416 CVE-2018-12363: A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a pointer referencing it. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60
nvd
CVE-2020-15659P3HIGHCVSS 8.8fixed in 68.11≥ 78.0, < 78.1.0+2 more2020-08-10
CVE-2020-15659 [HIGH] CWE-787 CVE-2020-15659: Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1,
nvd
CVE-2026-12291P3UNKNOWNfixed in Firefox ESR 140.12
CVE-2026-12291 Mozilla Foundation Security Advisory 2026-58: CVE-2026-12291 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12291 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-16362P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16362 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16362 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16362 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-74950P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74950 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74950 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74950 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2018-12391P3HIGHCVSS 8.8fixed in 60.3≥ unspecified, < 60.32019-02-28
CVE-2018-12391 [HIGH] CWE-863 CVE-2018-12391: During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins i During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of
nvd
CVE-2020-15673P3HIGHCVSS 8.8fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15673 [HIGH] CWE-416 CVE-2020-15673: Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of t Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2019-17008P3HIGHCVSS 8.8fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17008 [HIGH] CWE-416 CVE-2019-17008: When using nested workers, a use-after-free could occur during worker destruction. This resulted in When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2019-11740P3HIGHCVSS 8.8≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11740 [HIGH] CWE-787 CVE-2019-11740: Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird
nvd
CVE-2021-23978P3HIGHCVSS 8.8fixed in 78.82021-02-26
CVE-2021-23978 [HIGH] CWE-787 CVE-2021-23978: Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of t Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2020-26968P3HIGHCVSS 8.8fixed in 78.52020-12-09
CVE-2020-26968 [HIGH] CWE-787 CVE-2020-26968: Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of t Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2021-23999P3HIGHCVSS 8.8fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-23999 [HIGH] CWE-269 CVE-2021-23999: If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the Sys If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional privileges that should not be granted to web content. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2021-23964P3HIGHCVSS 8.8fixed in 78.72021-02-26
CVE-2021-23964 [HIGH] CWE-787 CVE-2021-23964: Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of t Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvd
CVE-2021-43534P3HIGHCVSS 8.8fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-43534 [HIGH] CWE-787 CVE-2021-43534: Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.
nvd
CVE-2023-6859P3HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6859 [HIGH] CWE-416 CVE-2023-6859: A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerabili A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2020-12406P3HIGHCVSS 8.8fixed in 68.9.0≥ unspecified, < 68.92020-07-09
CVE-2020-12406 [HIGH] CWE-345 CVE-2020-12406: Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resul Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2022-38477P3HIGHCVSS 8.8fixed in 102.2≥ unspecified, < 102.22022-12-22
CVE-2022-38477 [HIGH] CWE-787 CVE-2022-38477: Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in F Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.2, Thunderbird <
nvd
CVE-2022-22751P3HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22751 [HIGH] CWE-787 CVE-2022-22751: Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Mozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve Fink reported memory safety bugs present in Firefox 95 and Firefox ESR 91.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited t
nvd
CVE-2023-32215P3HIGHCVSS 8.8fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32215 [HIGH] CWE-787 CVE-2023-32215: Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112 and Firefox ESR 102.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been
nvd
CVE-2022-22761P3HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22761 [HIGH] CWE-693 CVE-2022-22761: Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing t Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase