Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 22 of 49
CVE-2020-6825P3CRITICALCVSS 9.8fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6825 [CRITICAL] CWE-787 CVE-2020-6825: Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bug
Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0
nvd
CVE-2020-6828P3HIGHCVSS 7.5fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6828 [HIGH] CWE-22 CVE-2020-6828: A malicious Android application could craft an Intent that would have been processed by Firefox for
A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary malicious preference values. Control of arbitrary preferences can lead to sufficient c
nvd
CVE-2018-12362P3HIGHCVSS 8.8fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12362 [HIGH] CWE-190 CVE-2018-12362: An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Ext
An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2024-10466P3HIGHCVSS 7.5≥ unspecified, < 128.42024-10-29
CVE-2024-10466 [HIGH] CWE-400 CVE-2024-10466: By sending a specially crafted push message, a remote server could have hung the parent process, cau
By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-6746P3HIGHCVSS 7.5fixed in Firefox ESR 140.10
CVE-2026-6746 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6746
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6746
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-8949P3HIGHCVSS 7.5fixed in Firefox ESR 140.11
CVE-2026-8949 [HIGH] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8949
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8949
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-8946P3HIGHCVSS 7.5fixed in Firefox ESR 115.36
CVE-2026-8946 [HIGH] Mozilla Foundation Security Advisory 2026-47: CVE-2026-8946
Mozilla Foundation Security Advisory 2026-47
CVE: CVE-2026-8946
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.36
mozilla
CVE-2026-8954P3HIGHCVSS 7.5fixed in Firefox ESR 140.11
CVE-2026-8954 [HIGH] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8954
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8954
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-6749P3HIGHCVSS 7.5fixed in Firefox ESR 115.35
CVE-2026-6749 [HIGH] Mozilla Foundation Security Advisory 2026-31: CVE-2026-6749
Mozilla Foundation Security Advisory 2026-31
CVE: CVE-2026-6749
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35
mozilla
CVE-2014-1533P3CRITICALCVSS 10.0v24.2v24.3+2 more2014-06-11
CVE-2014-1533 [CRITICAL] CVE-2014-1533: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2026-6759P3HIGHCVSS 7.5fixed in Firefox ESR 140.10
CVE-2026-6759 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6759
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6759
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2018-12360P3HIGHCVSS 8.8fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12360 [HIGH] CWE-416 CVE-2018-12360: A use-after-free vulnerability can occur when deleting an input element during a mutation event hand
A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2015-2724P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2724 [CRITICAL] CWE-119 CVE-2015-2724: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2020-12417P3HIGHCVSS 8.8fixed in 68.10.0≥ unspecified, < 68.102020-07-09
CVE-2020-12417 [HIGH] CWE-617 CVE-2020-12417: Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier,
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2020-6806P3HIGHCVSS 8.8fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6806 [HIGH] CWE-125 CVE-2020-6806: By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the en
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
nvd
CVE-2026-6751P3HIGHCVSS 7.3fixed in Firefox ESR 140.10
CVE-2026-6751 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6751
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6751
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-12324P3HIGHCVSS 7.3fixed in Firefox ESR 140.12
CVE-2026-12324 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12324
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12324
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-16379P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16379 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16379
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-16379
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
mozilla
CVE-2019-11752P3HIGHCVSS 8.8≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11752 [HIGH] CWE-416 CVE-2019-11752: It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion
It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
nvd
CVE-2017-7752P3HIGHCVSS 8.8≥ unspecified, < 52.22018-06-11
CVE-2017-7752 [HIGH] CWE-416 CVE-2017-7752: A use-after-free vulnerability during specific user interactions with the input method editor (IME)
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash but would require specific user interaction to trigger. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd