cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 23 of 49
CVE-2019-17012P3HIGHCVSS 8.8fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17012 [HIGH] CWE-787 CVE-2019-17012: Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of t Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2020-12420P3HIGHCVSS 8.8fixed in 68.10.0≥ unspecified, < 68.102020-07-09
CVE-2020-12420 [HIGH] CWE-362 CVE-2020-12420: When trying to connect to a STUN server, a race condition could have caused a use-after-free of a po When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2019-11746P3HIGHCVSS 8.8≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11746 [HIGH] CWE-416 CVE-2019-11746: A use-after-free vulnerability can occur while manipulating video elements if the body is freed whil A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
nvd
CVE-2020-12410P3HIGHCVSS 8.8fixed in 68.8.0≥ unspecified, < 68.92020-07-09
CVE-2020-12410 [HIGH] CWE-787 CVE-2020-12410: Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of t Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2019-11764P3HIGHCVSS 8.8fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11764 [HIGH] CWE-787 CVE-2019-11764: Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2021-29988P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.132021-08-17
CVE-2021-29988 [HIGH] CWE-125 CVE-2021-29988: Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of b Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2019-11757P3HIGHCVSS 8.8fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11757 [HIGH] CWE-416 CVE-2019-11757: When following the value's prototype chain, it was possible to retain a reference to a locale, delet When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2019-11758P3HIGHCVSS 8.8fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11758 [HIGH] CWE-787 CVE-2019-11758: Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total S Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Fi
nvd
CVE-2020-35112P3HIGHCVSS 8.8fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-35112 [HIGH] CVE-2020-35112: If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the download If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other ope
nvd
CVE-2019-11751P3HIGHCVSS 8.8fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11751 [HIGH] CWE-88 CVE-2019-11751: Logging-related command line parameters are not properly sanitized when Firefox is launched by anoth Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as the Windows 'Startup' folder. *Note: this issue only affects Firefox on Windows operating systems.*. Th
nvd
CVE-2023-25732P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25732 [HIGH] CWE-787 CVE-2023-25732: When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input bein When encoding data from an inputStream in xpcom the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2023-29539P3HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29539 [HIGH] CWE-476 CVE-2023-29539: When handling the filename directive in the Content-Disposition header, the filename would be trunca When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for An
nvd
CVE-2018-12393P3HIGHCVSS 7.5fixed in 60.3≥ unspecified, < 60.32019-02-28
CVE-2018-12393 [HIGH] CWE-190 CVE-2018-12393: A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox
nvd
CVE-2023-25746P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25746 [HIGH] CWE-787 CVE-2023-25746: Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corrup Memory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.8 and Firefox ESR < 102.8.
nvd
CVE-2022-31740P3HIGHCVSS 8.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31740 [HIGH] CWE-119 CVE-2022-31740: On arm64, WASM code could have resulted in incorrect assembly generation leading to a register alloc On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2017-5396P3CRITICALCVSS 9.8≥ unspecified, < 45.72018-06-11
CVE-2017-5396 [CRITICAL] CWE-416 CVE-2017-5396: A use-after-free vulnerability in the Media Decoder when working with media files when some events a A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2018-18501P3CRITICALCVSS 9.8fixed in 60.5≥ unspecified, < 60.52019-02-05
CVE-2018-18501 [CRITICAL] CWE-119 CVE-2018-18501: Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firef Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox <
nvd
CVE-2018-5155P3CRITICALCVSS 9.8≥ unspecified, < 52.82018-06-11
CVE-2018-5155 [CRITICAL] CWE-416 CVE-2018-5155: A use-after-free vulnerability can occur while adjusting layout during SVG animations with text path A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
nvd
CVE-2015-0818P3HIGHCVSS 7.5v31.1v31.2+3 more2015-03-24
CVE-2015-0818 [HIGH] CWE-264 CVE-2015-0818: Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow rem Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving SVG hash navigation.
nvd
CVE-2017-7819P3CRITICALCVSS 9.8≥ unspecified, < 52.42018-06-11
CVE-2017-7819 [CRITICAL] CWE-416 CVE-2017-7819: A use-after-free vulnerability can occur in design mode when image objects are resized if objects re A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been freed from memory. This results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase