Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 16 of 45
CVE-2017-7784P3CRITICALCVSS 9.8fixed in 52.32018-06-11
CVE-2017-7784 [CRITICAL] CWE-416 CVE-2017-7784: A use-after-free vulnerability can occur when reading an image observer during frame reconstruction
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2019-9815P3HIGHCVSS 8.1fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9815 [HIGH] CWE-203 CVE-2019-9815: If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications running untrusted code in a thread through a new sysctl. Firefox now makes use of it on the main thread and any worker threads. *Note: users need to update
nvd
CVE-2016-9898P3CRITICALCVSS 9.8≥ unspecified, < 45.62018-06-11
CVE-2016-9898 [CRITICAL] CWE-416 CVE-2016-9898: Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Edit
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-5429P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5429 [CRITICAL] CWE-119 CVE-2017-5429: Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Fi
nvd
CVE-2018-12378P3CRITICALCVSS 9.8≥ unspecified, < 60.22018-10-18
CVE-2018-12378 [CRITICAL] CWE-416 CVE-2018-12378: A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by Ja
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2018-12377P3CRITICALCVSS 9.8≥ unspecified, < 60.22018-10-18
CVE-2018-12377 [CRITICAL] CWE-416 CVE-2018-12377: A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstan
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2017-7792P3CRITICALCVSS 9.8≥ unspecified, < 52.32018-06-11
CVE-2017-7792 [CRITICAL] CWE-119 CVE-2017-7792: A buffer overflow will occur when viewing a certificate in the certificate manager if the certificat
A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2017-5380P3CRITICALCVSS 9.8≥ unspecified, < 45.72018-06-11
CVE-2017-5380 [CRITICAL] CWE-416 CVE-2017-5380: A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulner
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2018-5098P3CRITICALCVSS 9.8≥ unspecified, < 52.62018-06-11
CVE-2018-5098 [CRITICAL] CWE-416 CVE-2018-5098: A use-after-free vulnerability can occur when form input elements, focus, and selections are manipul
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2018-12395P3HIGHCVSS 7.5fixed in 60.3≥ unspecified, < 60.32019-02-28
CVE-2018-12395 [HIGH] CVE-2018-12395: By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain re
By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
nvd
CVE-2017-7800P3CRITICALCVSS 9.8≥ unspecified, < 52.32018-06-11
CVE-2017-7800 [CRITICAL] CWE-416 CVE-2017-7800: A use-after-free vulnerability can occur in WebSockets when the object holding the connection is fre
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2017-7749P3CRITICALCVSS 9.8≥ unspecified, < 52.22018-06-11
CVE-2017-7749 [CRITICAL] CWE-416 CVE-2017-7749: A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2020-12395P3CRITICALCVSS 9.8fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12395 [CRITICAL] CWE-787 CVE-2020-12395: Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird <
nvd
CVE-2019-9788P3CRITICALCVSS 9.8≥ unspecified, < 60.62019-04-26
CVE-2019-9788 [CRITICAL] CWE-787 CVE-2019-9788: Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox
Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.
nvd
CVE-2019-9800P3CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9800 [CRITICAL] CWE-787 CVE-2019-9800: Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox
Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and
nvd
CVE-2019-11691P3CRITICALCVSS 9.8fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-11691 [CRITICAL] CWE-416 CVE-2019-11691: A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, ca
A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2019-11733P3CRITICALCVSS 9.8≥ unspecified, < 68.0.22019-09-27
CVE-2019-11733 [CRITICAL] CWE-287 CVE-2019-11733: When a master password is set, it is required to be entered again before stored passwords can be acc
When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering the master password if the master password had been previously entered i
nvd
CVE-2017-5444P3HIGHCVSS 7.5≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5444 [HIGH] CWE-119 CVE-2017-5444: A buffer overflow vulnerability while parsing "application/http-index-format" format content when th
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2021-4129P3CRITICALCVSS 9.8fixed in 91.4.0≥ unspecified, < 91.4.02022-12-22
CVE-2021-4129 [CRITICAL] CWE-787 CVE-2021-4129: Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith,
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. Thi
nvd
CVE-2022-29917P3CRITICALCVSS 9.8fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29917 [CRITICAL] CWE-787 CVE-2022-29917: Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team report
Mozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99 and Firefox ESR 91.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affect
nvd