cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 17 of 45
CVE-2024-11704P3CRITICALCVSS 9.8≥ unspecified, < 128.72024-11-26
CVE-2024-11704 [CRITICAL] CWE-415 CVE-2024-11704: A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an erro A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133, Thunderbird < 133, Firefox ESR < 128.7, and Thunderbird < 128.7.
nvd
CVE-2024-6604P3HIGHCVSS 7.5≥ unspecified, < 115.132024-07-09
CVE-2024-6604 [HIGH] CWE-120 CVE-2024-6604: Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2024-8900P3HIGHCVSS 7.5≥ unspecified, < 128.32024-09-17
CVE-2024-8900 [HIGH] CWE-732 CVE-2024-8900: An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain se An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129, Firefox ESR < 128.3, and Thunderbird < 128.3.
nvd
CVE-2016-9066P3HIGHCVSS 7.5≥ unspecified, < 45.52018-06-11
CVE-2016-9066 [HIGH] CWE-119 CVE-2016-9066: A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2018-12363P3HIGHCVSS 8.8fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12363 [HIGH] CWE-416 CVE-2018-12363: A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a pointer referencing it. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60
nvd
CVE-2026-6772P3HIGHCVSS 7.5fixed in Firefox ESR 115.35
CVE-2026-6772 [HIGH] Mozilla Foundation Security Advisory 2026-31: CVE-2026-6772 Mozilla Foundation Security Advisory 2026-31 CVE: CVE-2026-6772 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.35
mozilla
CVE-2026-6766P3HIGHCVSS 7.5fixed in Firefox ESR 140.10
CVE-2026-6766 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6766 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6766 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-12312P3HIGHCVSS 7.5fixed in Firefox ESR 140.12
CVE-2026-12312 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12312 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12312 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12314P3HIGHCVSS 7.5fixed in Firefox ESR 140.12
CVE-2026-12314 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12314 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12314 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12310P3HIGHCVSS 7.5fixed in Firefox ESR 140.12
CVE-2026-12310 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12310 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12310 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2015-2740P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2740 [CRITICAL] CWE-119 CVE-2015-2740: Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39. Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
nvd
CVE-2020-6800P3HIGHCVSS 8.8fixed in 68.5.02020-03-02
CVE-2020-6800 [HIGH] CWE-787 CVE-2020-6800: Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product
nvd
CVE-2015-2743P3HIGHCVSS 7.5v31.1v31.2+5 more2015-07-06
CVE-2015-2743 [HIGH] CWE-17 CVE-2015-2743: PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.
nvd
CVE-2019-11740P3HIGHCVSS 8.8≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11740 [HIGH] CWE-787 CVE-2019-11740: Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird
nvd
CVE-2021-38496P3HIGHCVSS 8.8fixed in 78.15≥ unspecified, < 91.2+1 more2021-11-03
CVE-2021-38496 [HIGH] CWE-416 CVE-2021-38496: During operations on MessageTasks, a task may have been removed while it was still scheduled, result During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
nvd
CVE-2020-12410P3HIGHCVSS 8.8fixed in 68.8.0≥ unspecified, < 68.92020-07-09
CVE-2020-12410 [HIGH] CWE-787 CVE-2020-12410: Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of t Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2021-29985P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.132021-08-17
CVE-2021-29985 [HIGH] CWE-416 CVE-2021-29985: A use-after-free vulnerability in media channels could have led to memory corruption and a potential A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2021-29984P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.132021-08-17
CVE-2021-29984 [HIGH] CWE-787 CVE-2021-29984: Instruction reordering resulted in a sequence of instructions that would cause an object to be incor Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2021-29967P3HIGHCVSS 8.8fixed in 78.11≥ unspecified, < 78.112021-06-24
CVE-2021-29967 [HIGH] CWE-787 CVE-2021-29967: Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
nvd
CVE-2020-6805P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6805 [HIGH] CWE-416 CVE-2020-6805: When removing data about an origin whose tab was recently closed, a use-after-free could occur in th When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase