cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 23 of 45
CVE-2017-7753P3CRITICALCVSS 9.1≥ unspecified, < 52.32018-06-11
CVE-2017-7753 [CRITICAL] CWE-125 CVE-2017-7753: An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, usi An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2024-3852P3HIGHCVSS 7.5≥ unspecified, < 115.102024-04-16
CVE-2024-3852 [HIGH] CWE-386 CVE-2024-3852: GetBoundName could return the wrong version of an object when JIT optimizations were applied. This v GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2024-10459P3HIGHCVSS 7.5≥ unspecified, < 128.4≥ unspecified, < 115.172024-10-29
CVE-2024-10459 [HIGH] CWE-416 CVE-2024-10459: An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentia An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-6747P3HIGHCVSS 7.5fixed in Firefox ESR 140.10
CVE-2026-6747 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6747 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6747 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-6754P3HIGHCVSS 7.5fixed in Firefox ESR 115.35
CVE-2026-6754 [HIGH] Mozilla Foundation Security Advisory 2026-31: CVE-2026-6754 Mozilla Foundation Security Advisory 2026-31 CVE: CVE-2026-6754 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.35
mozilla
CVE-2026-12305P3HIGHCVSS 7.5fixed in Firefox ESR 140.12
CVE-2026-12305 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12305 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12305 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2015-2725P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2725 [CRITICAL] CWE-119 CVE-2015-2725: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2024-6603P3HIGHCVSS 7.4≥ unspecified, < 115.132024-07-09
CVE-2024-6603 [HIGH] CWE-823 CVE-2024-6603: In an out-of-memory scenario an allocation could fail but free would have been called on the pointer In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2018-12361P3HIGHCVSS 8.8fixed in 60.1≥ unspecified, < 60.12018-10-18
CVE-2018-12361 [HIGH] CWE-190 CVE-2018-12361: An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
nvd
CVE-2026-8947P3HIGHCVSS 7.3fixed in Firefox ESR 115.36
CVE-2026-8947 [HIGH] Mozilla Foundation Security Advisory 2026-47: CVE-2026-8947 Mozilla Foundation Security Advisory 2026-47 CVE: CVE-2026-8947 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.36
mozilla
CVE-2014-1562P3CRITICALCVSS 10.0v24.2v24.3+4 more2014-09-03
CVE-2014-1562 [CRITICAL] CWE-119 CVE-2014-1562: Unspecified vulnerability in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 24.x bef Unspecified vulnerability in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2026-8090P3HIGHCVSS 7.3fixed in Firefox ESR 115.35.2
CVE-2026-8090 [HIGH] Mozilla Foundation Security Advisory 2026-42: CVE-2026-8090 Mozilla Foundation Security Advisory 2026-42 CVE: CVE-2026-8090 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.35.2
mozilla
CVE-2026-6752P3HIGHCVSS 7.3fixed in Firefox ESR 115.35
CVE-2026-6752 [HIGH] Mozilla Foundation Security Advisory 2026-31: CVE-2026-6752 Mozilla Foundation Security Advisory 2026-31 CVE: CVE-2026-6752 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.35
mozilla
CVE-2026-12292P3UNKNOWNfixed in Firefox ESR 140.12
CVE-2026-12292 Mozilla Foundation Security Advisory 2026-58: CVE-2026-12292 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12292 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2019-17024P3HIGHCVSS 8.8fixed in 68.4vbefore 68.42020-01-08
CVE-2019-17024 [HIGH] CWE-787 CVE-2019-17024: Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of t Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2017-5436P3HIGHCVSS 8.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5436 [HIGH] CWE-787 CVE-2017-5436: An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2016-9905P3HIGHCVSS 8.8≥ unspecified, < 45.62018-06-11
CVE-2016-9905 [HIGH] CWE-284 CVE-2016-9905: A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. T A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
nvd
CVE-2018-5130P3HIGHCVSS 8.8≥ unspecified, < 52.72018-06-11
CVE-2018-5130 [HIGH] CWE-20 CVE-2018-5130: When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstance When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
nvd
CVE-2026-7323P3UNKNOWNfixed in Firefox ESR 140.10.1
CVE-2026-7323 Mozilla Foundation Security Advisory 2026-36: CVE-2026-7323 Mozilla Foundation Security Advisory 2026-36 CVE: CVE-2026-7323 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10.1
mozilla
CVE-2020-12419P3HIGHCVSS 8.8fixed in 68.10≥ unspecified, < 68.102020-07-09
CVE-2020-12419 [HIGH] CWE-416 CVE-2020-12419: When processing callbacks that occurred during window flushing in the parent process, the associated When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase