Mozilla Firefox Esr vulnerabilities

776 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
776
CISA KEV
9
actively exploited
Public exploits
18
Exploited in wild
13
Severity breakdown
CRITICAL186HIGH315MEDIUM269LOW6

Vulnerabilities

Page 22 of 39
CVE-2020-12417HIGHCVSS 8.8fixed in 68.10.0≥ unspecified, < 68.102020-07-09
CVE-2020-12417 [HIGH] CWE-617 CVE-2020-12417: Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects Firefox on ARM64 platforms.* This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
cvelistv5nvd
CVE-2020-12410HIGHCVSS 8.8fixed in 68.8.0≥ unspecified, < 68.92020-07-09
CVE-2020-12410 [HIGH] CWE-787 CVE-2020-12410: Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of t Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
cvelistv5nvd
CVE-2018-12371HIGHCVSS 8.8≥ unspecified, < 60.12020-07-09
CVE-2018-12371 [HIGH] CWE-190 CVE-2018-12371: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.
cvelistv5nvd
CVE-2020-12420HIGHCVSS 8.8fixed in 68.10.0≥ unspecified, < 68.102020-07-09
CVE-2020-12420 [HIGH] CWE-362 CVE-2020-12420: When trying to connect to a STUN server, a race condition could have caused a use-after-free of a po When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
cvelistv5nvd
CVE-2020-12418MEDIUMCVSS 6.5fixed in 68.10≥ unspecified, < 68.102020-07-09
CVE-2020-12418 [MEDIUM] CWE-125 CVE-2020-12418: Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking proce Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
cvelistv5nvd
CVE-2020-12405MEDIUMCVSS 5.3fixed in 68.9.0≥ unspecified, < 68.92020-07-09
CVE-2020-12405 [MEDIUM] CWE-362 CVE-2020-12405: When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
cvelistv5nvd
CVE-2020-12399MEDIUMCVSS 4.4fixed in 68.9.0≥ unspecified, < 68.92020-07-09
CVE-2020-12399 [MEDIUM] CWE-203 CVE-2020-12399: NSS has shown timing differences when performing DSA signatures, which was exploitable and could eve NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
cvelistv5nvd
CVE-2020-12421MEDIUMCVSS 6.5fixed in 68.10.0≥ unspecified, < 68.102020-07-09
CVE-2020-12421 [MEDIUM] CWE-295 CVE-2020-12421: When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected ( When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
cvelistv5nvd
CVE-2020-12389CRITICALCVSS 10.0fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12389 [CRITICAL] CWE-20 CVE-2020-12389: The Firefox content processes did not sufficiently lockdown access control which could result in a s The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
cvelistv5nvd
CVE-2020-12388CRITICALCVSS 10.0fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12388 [CRITICAL] CWE-20 CVE-2020-12388: The Firefox content processes did not sufficiently lockdown access control which could result in a s The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
cvelistv5nvd
CVE-2020-12395CRITICALCVSS 9.8fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12395 [CRITICAL] CWE-787 CVE-2020-12395: Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird <
cvelistv5nvd
CVE-2020-6831CRITICALCVSS 9.8fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-6831 [CRITICAL] CWE-787 CVE-2020-6831: A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
cvelistv5nvd
CVE-2020-12387HIGHCVSS 8.1fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12387 [HIGH] CWE-362 CVE-2020-12387: A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. Th A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
cvelistv5nvd
CVE-2020-12393HIGHCVSS 7.8fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12393 [HIGH] CWE-78 CVE-2020-12393: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a req The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows
cvelistv5nvd
CVE-2020-12392MEDIUMCVSS 5.5fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12392 [MEDIUM] CWE-22 CVE-2020-12392: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and
cvelistv5nvd
CVE-2020-6825CRITICALCVSS 9.8fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6825 [CRITICAL] CWE-787 CVE-2020-6825: Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bug Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0
cvelistv5nvd
CVE-2020-6821HIGHCVSS 7.5fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6821 [HIGH] CWE-908 CVE-2020-6821: When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSub When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
cvelistv5nvd
CVE-2020-6828HIGHCVSS 7.5fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6828 [HIGH] CWE-22 CVE-2020-6828: A malicious Android application could craft an Intent that would have been processed by Firefox for A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a file overwrite in the user's profile directory. One exploitation vector for this would be to supply a user.js file providing arbitrary malicious preference values. Control of arbitrary preferences can lead to sufficient c
cvelistv5nvd
CVE-2020-6819HIGHCVSS 8.1KEV≥ unspecified, < 68.6.12020-04-24
CVE-2020-6819 [HIGH] CWE-362 CVE-2020-6819: Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-a Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.
cvelistv5nvd
CVE-2020-6822HIGHCVSS 8.8fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6822 [HIGH] CWE-787 CVE-2020-6822: On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
cvelistv5nvd