Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 20 of 49
CVE-2021-29970P3HIGHCVSS 8.8fixed in 78.12≥ unspecified, < 78.122021-08-05
CVE-2021-29970 [HIGH] CWE-416 CVE-2021-29970: A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially expl
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be triggered when accessibility was enabled.*. This vulnerability affects Thunderbird < 78.12, Firefox ESR < 78.12, and Firefox < 90.
nvd
CVE-2021-29984P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.132021-08-17
CVE-2021-29984 [HIGH] CWE-787 CVE-2021-29984: Instruction reordering resulted in a sequence of instructions that would cause an object to be incor
Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collection. This led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2021-29967P3HIGHCVSS 8.8fixed in 78.11≥ unspecified, < 78.112021-06-24
CVE-2021-29967 [HIGH] CWE-787 CVE-2021-29967: Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of
Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
nvd
CVE-2020-6805P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6805 [HIGH] CWE-416 CVE-2020-6805: When removing data about an origin whose tab was recently closed, a use-after-free could occur in th
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2020-6807P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6807 [HIGH] CWE-416 CVE-2020-6807: When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> t
When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2021-23960P3HIGHCVSS 8.8fixed in 78.72021-02-26
CVE-2021-23960 [HIGH] CVE-2021-23960: Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, a
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvd
CVE-2021-38501P3HIGHCVSS 8.8fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38501 [HIGH] CVE-2021-38501: Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of t
Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvd
CVE-2022-34484P3HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-34484 [HIGH] CWE-416 CVE-2022-34484: The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of th
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11
nvd
CVE-2022-42928P3HIGHCVSS 8.8fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42928 [HIGH] CWE-476 CVE-2022-42928: Certain types of allocations were missing annotations that, if the Garbage Collector was in a specif
Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvd
CVE-2023-37202P3HIGHCVSS 8.8fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37202 [HIGH] CWE-416 CVE-2023-37202: Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartmen
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2022-2505P3HIGHCVSS 8.8fixed in 102.1≥ unspecified, < 102.12022-12-22
CVE-2022-2505 [HIGH] CWE-787 CVE-2022-2505: Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102.
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
nvd
CVE-2022-46878P3HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46878 [HIGH] CWE-787 CVE-2022-46878: Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported
Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 108, Firef
nvd
CVE-2023-25735P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25735 [HIGH] CWE-416 CVE-2023-25735: Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartmen
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2018-5095P3CRITICALCVSS 9.8≥ unspecified, < 52.62018-06-11
CVE-2018-5095 [CRITICAL] CWE-190 CVE-2018-5095: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so
An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2022-45421P3HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45421 [HIGH] CWE-787 CVE-2022-45421: Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thund
Mozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox
nvd
CVE-2022-28289P3HIGHCVSS 8.8fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28289 [HIGH] CWE-787 CVE-2022-28289: Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mo
Mozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safety bugs present in Thunderbird 91.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability
nvd
CVE-2017-7785P3CRITICALCVSS 9.8≥ unspecified, < 52.32018-06-11
CVE-2017-7785 [CRITICAL] CWE-119 CVE-2017-7785: A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attribute
A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2022-22763P3HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22763 [HIGH] CWE-362 CVE-2022-22763: When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point
When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2017-5398P3CRITICALCVSS 9.8≥ unspecified, < 45.82018-06-11
CVE-2017-5398 [CRITICAL] CWE-119 CVE-2017-5398: Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory c
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5400P3CRITICALCVSS 9.8≥ unspecified, < 45.82018-06-11
CVE-2017-5400 [CRITICAL] CWE-119 CVE-2017-5400: JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protection
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd