cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 2 of 45
CVE-2018-5159P2CRITICALCVSS 9.8PoC≥ unspecified, < 52.82018-06-11
CVE-2018-5159 [CRITICAL] CWE-190 CVE-2018-5159: An integer overflow can occur in the Skia library due to 32-bit integer use in an array without inte An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially exploitable crash triggerable by web content. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8
nvd
CVE-2015-4000P3LOWCVSS 3.7PoCv31.82015-05-21
CVE-2015-4000 [LOW] CWE-310 CVE-2015-4000: The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, a
nvd
CVE-2017-5447P2CRITICALCVSS 9.1PoC≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5447 [CRITICAL] CWE-416 CVE-2017-5447: An out-of-bounds read during the processing of glyph widths during text layout. This results in a po An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-5404P2CRITICALCVSS 9.8PoC≥ unspecified, < 45.82018-06-11
CVE-2017-5404 [CRITICAL] CWE-416 CVE-2017-5404: A use-after-free error can occur when manipulating ranges in selections with one node inside a nativ A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5465P2CRITICALCVSS 9.1PoC≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5465 [CRITICAL] CWE-125 CVE-2017-5465: An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and a An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2019-9792P2CRITICALCVSS 9.8PoC≥ unspecified, < 60.62019-04-26
CVE-2019-9792 [CRITICAL] CWE-787 CVE-2019-9792: The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the r The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
nvd
CVE-2019-9813P3HIGHCVSS 8.8PoC≥ unspecified, < 60.6.12019-04-26
CVE-2019-9813 [HIGH] CWE-843 CVE-2019-9813: Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can b Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.
nvd
CVE-2023-6856P2HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6856 [HIGH] CWE-787 CVE-2023-6856: The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on syst The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2019-9816P3MEDIUMCVSS 5.9PoCfixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9816 [MEDIUM] CWE-843 CVE-2019-9816: A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbi
nvd
CVE-2022-2200P3HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-2200 [HIGH] CWE-1321 CVE-2022-2200: If an object prototype was corrupted by an attacker, they would have been able to set undesired attr If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2026-16412P3CRITICALCVSS 9.8fixed in Firefox ESR 140.13
CVE-2026-16412 [CRITICAL] Mozilla Foundation Security Advisory 2026-70: CVE-2026-16412 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16412 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2024-8381P3CRITICALCVSS 9.8fixed in 115.15≥ 128.0, < 128.2+2 more2024-09-03
CVE-2024-8381 [CRITICAL] CWE-843 CVE-2024-8381: A potentially exploitable type confusion could be triggered when looking up a property name on an ob A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
nvd
CVE-2021-38503P3CRITICALCVSS 10.0fixed in 91.3≥ unspecified, < 91.32021-12-08
CVE-2021-38503 [CRITICAL] CWE-863 CVE-2021-38503: The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypas The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2026-16361P3CRITICALCVSS 9.8fixed in Firefox ESR 140.13
CVE-2026-16361 [CRITICAL] Mozilla Foundation Security Advisory 2026-70: CVE-2026-16361 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16361 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2023-29542P3CRITICALCVSS 9.8fixed in 102.10≥ unspecified, < 102.102023-06-19
CVE-2023-29542 [CRITICAL] CVE-2023-29542: A newline in a filename could have been used to bypass the file extension security mechanisms that r A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerab
nvd
CVE-2026-6771P3CRITICALCVSS 9.8fixed in Firefox ESR 140.10
CVE-2026-6771 [CRITICAL] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6771 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6771 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2018-12386P3HIGHCVSS 8.1≥ unspecified, < 60.2.22018-10-18
CVE-2018-12386 [HIGH] CWE-704 CVE-2018-12386: A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arb A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.
nvd
CVE-2016-6354P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12016-09-21
CVE-2016-6354 [CRITICAL] CWE-119 CVE-2016-6354: Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow conte Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.
nvd
CVE-2021-4140P3CRITICALCVSS 10.0fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2021-4140 [CRITICAL] CWE-91 CVE-2021-4140: It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. Th It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2020-6811P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6811 [HIGH] CWE-77 CVE-2020-6811: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a req The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Fire
nvd
Mozilla Firefox Esr vulnerabilities | cvebase