Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 20 of 45
CVE-2020-12393P3HIGHCVSS 7.8fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12393 [HIGH] CWE-78 CVE-2020-12393: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a req
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows
nvd
CVE-2020-6825P3CRITICALCVSS 9.8fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6825 [CRITICAL] CWE-787 CVE-2020-6825: Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bug
Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0
nvd
CVE-2017-7804P3HIGHCVSS 7.5≥ unspecified, < 52.32018-06-11
CVE-2017-7804 [HIGH] CWE-20 CVE-2017-7804: The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code
The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to bypass existing memory protections in this situation. Note: This attack only affects Windows operating systems. Other operating
nvd
CVE-2020-6828P3HIGHCVSS 7.5fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6828 [HIGH] CWE-22 CVE-2020-6828: A malicious Android application could craft an Intent that would have been processed by Firefox for
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary malicious preference values. Control of arbitrary preferences can lead to sufficient c
nvd
CVE-2018-12362P3HIGHCVSS 8.8fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12362 [HIGH] CWE-190 CVE-2018-12362: An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Ext
An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2024-10466P3HIGHCVSS 7.5≥ unspecified, < 128.42024-10-29
CVE-2024-10466 [HIGH] CWE-400 CVE-2024-10466: By sending a specially crafted push message, a remote server could have hung the parent process, cau
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-6746P3HIGHCVSS 7.5fixed in Firefox ESR 140.10
CVE-2026-6746 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6746
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6746
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-8949P3HIGHCVSS 7.5fixed in Firefox ESR 140.11
CVE-2026-8949 [HIGH] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8949
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8949
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-8946P3HIGHCVSS 7.5fixed in Firefox ESR 115.36
CVE-2026-8946 [HIGH] Mozilla Foundation Security Advisory 2026-47: CVE-2026-8946
Mozilla Foundation Security Advisory 2026-47
CVE: CVE-2026-8946
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.36
mozilla
CVE-2026-8954P3HIGHCVSS 7.5fixed in Firefox ESR 140.11
CVE-2026-8954 [HIGH] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8954
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8954
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-6749P3HIGHCVSS 7.5fixed in Firefox ESR 115.35
CVE-2026-6749 [HIGH] Mozilla Foundation Security Advisory 2026-31: CVE-2026-6749
Mozilla Foundation Security Advisory 2026-31
CVE: CVE-2026-6749
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35
mozilla
CVE-2026-6759P3HIGHCVSS 7.5fixed in Firefox ESR 140.10
CVE-2026-6759 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6759
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6759
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2018-12360P3HIGHCVSS 8.8fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12360 [HIGH] CWE-416 CVE-2018-12360: A use-after-free vulnerability can occur when deleting an input element during a mutation event hand
A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2026-16405P3HIGHCVSS 7.5fixed in Firefox ESR 140.13
CVE-2026-16405 [HIGH] Mozilla Foundation Security Advisory 2026-70: CVE-2026-16405
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-16405
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
mozilla
CVE-2014-1533P3CRITICALCVSS 10.0v24.2v24.3+2 more2014-06-11
CVE-2014-1533 [CRITICAL] CVE-2014-1533: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-2724P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2724 [CRITICAL] CWE-119 CVE-2015-2724: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2020-12417P3HIGHCVSS 8.8fixed in 68.10.0≥ unspecified, < 68.102020-07-09
CVE-2020-12417 [HIGH] CWE-617 CVE-2020-12417: Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier,
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2026-8090P3HIGHCVSS 7.3fixed in Firefox ESR 115.35.2
CVE-2026-8090 [HIGH] Mozilla Foundation Security Advisory 2026-42: CVE-2026-8090
Mozilla Foundation Security Advisory 2026-42
CVE: CVE-2026-8090
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35.2
mozilla
CVE-2026-6751P3HIGHCVSS 7.3fixed in Firefox ESR 140.10
CVE-2026-6751 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6751
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6751
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2020-6806P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6806 [HIGH] CWE-125 CVE-2020-6806: By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the en
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd