Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 17 of 49
CVE-2023-28176P3HIGHCVSS 8.8fixed in 102.9≥ unspecified, < 102.92023-06-02
CVE-2023-28176 [HIGH] CWE-787 CVE-2023-28176: Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence
Memory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd
CVE-2022-42932P3HIGHCVSS 8.8fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42932 [HIGH] CWE-787 CVE-2022-42932: Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developers Ashley Hale and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105 and Firefox ESR 102.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106, Firefox ESR < 102.4
nvd
CVE-2023-25737P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25737 [HIGH] CWE-704 CVE-2023-25737: An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undef
An invalid downcast from nsTextNode to SVGElement could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2023-29536P3HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29536 [HIGH] CWE-416 CVE-2023-29536: An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-con
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvd
CVE-2022-22764P3HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22764 [HIGH] CWE-787 CVE-2022-22764: Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in F
Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, an
nvd
CVE-2022-38473P3HIGHCVSS 8.8fixed in 91.13≥ unspecified, < 91.13+1 more2022-12-22
CVE-2022-38473 [HIGH] CWE-281 CVE-2022-38473: A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (su
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.
nvd
CVE-2023-25739P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25739 [HIGH] CWE-416 CVE-2023-25739: Module load requests that failed were not being checked as to whether or not they were cancelled cau
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in ScriptLoadContext. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2023-25744P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25744 [HIGH] CWE-787 CVE-2023-25744: Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence
Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
nvd
CVE-2024-7522P3HIGHCVSS 8.8fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7522 [HIGH] CWE-125 CVE-2024-7522: Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This v
Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2017-7786P3CRITICALCVSS 9.8fixed in 52.3≥ unspecified, < 52.32018-06-11
CVE-2017-7786 [CRITICAL] CWE-119 CVE-2017-7786: A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements.
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2023-4047P3HIGHCVSS 8.8≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4047 [HIGH] CWE-352 CVE-2023-4047: A bug in popup notifications delay calculation could have made it possible for an attacker to trick
A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2024-4770P3HIGHCVSS 8.8≥ unspecified, < 115.112024-05-14
CVE-2024-4770 [HIGH] CWE-416 CVE-2024-4770: When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. T
When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2019-9815P3HIGHCVSS 8.1fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9815 [HIGH] CWE-203 CVE-2019-9815: If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre
If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications running untrusted code in a thread through a new sysctl. Firefox now makes use of it on the main thread and any worker threads. *Note: users need to update
nvd
CVE-2017-5429P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5429 [CRITICAL] CWE-119 CVE-2017-5429: Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Fi
nvd
CVE-2018-12378P3CRITICALCVSS 9.8≥ unspecified, < 60.22018-10-18
CVE-2018-12378 [CRITICAL] CWE-416 CVE-2018-12378: A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by Ja
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2018-12377P3CRITICALCVSS 9.8≥ unspecified, < 60.22018-10-18
CVE-2018-12377 [CRITICAL] CWE-416 CVE-2018-12377: A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstan
A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.
nvd
CVE-2017-7792P3CRITICALCVSS 9.8≥ unspecified, < 52.32018-06-11
CVE-2017-7792 [CRITICAL] CWE-119 CVE-2017-7792: A buffer overflow will occur when viewing a certificate in the certificate manager if the certificat
A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2017-5380P3CRITICALCVSS 9.8≥ unspecified, < 45.72018-06-11
CVE-2017-5380 [CRITICAL] CWE-416 CVE-2017-5380: A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulner
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2018-12395P3HIGHCVSS 7.5fixed in 60.3≥ unspecified, < 60.32019-02-28
CVE-2018-12395 [HIGH] CVE-2018-12395: By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain re
By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
nvd
CVE-2018-5098P3CRITICALCVSS 9.8≥ unspecified, < 52.62018-06-11
CVE-2018-5098 [CRITICAL] CWE-416 CVE-2018-5098: A use-after-free vulnerability can occur when form input elements, focus, and selections are manipul
A use-after-free vulnerability can occur when form input elements, focus, and selections are manipulated by script content. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd