Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 19 of 49
CVE-2026-6766P3HIGHCVSS 7.5fixed in Firefox ESR 140.10
CVE-2026-6766 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6766
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6766
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-12312P3HIGHCVSS 7.5fixed in Firefox ESR 140.12
CVE-2026-12312 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12312
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12312
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12314P3HIGHCVSS 7.5fixed in Firefox ESR 140.12
CVE-2026-12314 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12314
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12314
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12310P3HIGHCVSS 7.5fixed in Firefox ESR 140.12
CVE-2026-12310 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12310
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12310
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2015-2740P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2740 [CRITICAL] CWE-119 CVE-2015-2740: Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.
Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
nvd
CVE-2026-74946P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74946 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74946
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74946
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74941P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74941 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74941
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74941
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74935P3UNKNOWNfixed in Firefox ESR 140.14
CVE-2026-74935 Mozilla Foundation Security Advisory 2026-76: CVE-2026-74935
Mozilla Foundation Security Advisory 2026-76
CVE: CVE-2026-74935
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.14
mozilla
CVE-2026-74939P3UNKNOWNfixed in Firefox ESR 140.14
CVE-2026-74939 Mozilla Foundation Security Advisory 2026-76: CVE-2026-74939
Mozilla Foundation Security Advisory 2026-76
CVE: CVE-2026-74939
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.14
mozilla
CVE-2026-74965P3UNKNOWNfixed in Firefox ESR 140.14
CVE-2026-74965 Mozilla Foundation Security Advisory 2026-76: CVE-2026-74965
Mozilla Foundation Security Advisory 2026-76
CVE: CVE-2026-74965
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.14
mozilla
CVE-2026-74953P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74953 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74953
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74953
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2020-6800P3HIGHCVSS 8.8fixed in 68.5.02020-03-02
CVE-2020-6800 [HIGH] CWE-787 CVE-2020-6800: Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firef
Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited through email in the Thunderbird product
nvd
CVE-2026-74947P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74947 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74947
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74947
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-16396P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16396 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16396
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-16396
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-74955P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74955 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74955
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74955
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2021-38496P3HIGHCVSS 8.8fixed in 78.15≥ unspecified, < 91.2+1 more2021-11-03
CVE-2021-38496 [HIGH] CWE-416 CVE-2021-38496: During operations on MessageTasks, a task may have been removed while it was still scheduled, result
During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbird < 91.2, Firefox ESR < 91.2, Firefox ESR < 78.15, and Firefox < 93.
nvd
CVE-2019-11711P3HIGHCVSS 8.8≥ unspecified, < 60.82019-07-23
CVE-2019-11711 [HIGH] CVE-2019-11711: When an inner window is reused, it does not consider the use of document.domain for cross-origin pro
When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vul
nvd
CVE-2020-15656P3HIGHCVSS 8.8fixed in 78.1≥ unspecified, < 78.12020-08-10
CVE-2020-15656 [HIGH] CWE-843 CVE-2020-15656: JIT optimizations involving the Javascript arguments object could confuse later optimizations. This
JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only moderate severity. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2015-2743P3HIGHCVSS 7.5v31.1v31.2+5 more2015-07-06
CVE-2015-2743 [HIGH] CWE-17 CVE-2015-2743: PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables
PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.
nvd
CVE-2021-29985P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.132021-08-17
CVE-2021-29985 [HIGH] CWE-416 CVE-2021-29985: A use-after-free vulnerability in media channels could have led to memory corruption and a potential
A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd