Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 23 of 45
CVE-2017-7753P3CRITICALCVSS 9.1≥ unspecified, < 52.32018-06-11
CVE-2017-7753 [CRITICAL] CWE-125 CVE-2017-7753: An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, usi
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2024-3852P3HIGHCVSS 7.5≥ unspecified, < 115.102024-04-16
CVE-2024-3852 [HIGH] CWE-386 CVE-2024-3852: GetBoundName could return the wrong version of an object when JIT optimizations were applied. This v
GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2024-10459P3HIGHCVSS 7.5≥ unspecified, < 128.4≥ unspecified, < 115.172024-10-29
CVE-2024-10459 [HIGH] CWE-416 CVE-2024-10459: An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentia
An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-6747P3HIGHCVSS 7.5fixed in Firefox ESR 140.10
CVE-2026-6747 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6747
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6747
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-6754P3HIGHCVSS 7.5fixed in Firefox ESR 115.35
CVE-2026-6754 [HIGH] Mozilla Foundation Security Advisory 2026-31: CVE-2026-6754
Mozilla Foundation Security Advisory 2026-31
CVE: CVE-2026-6754
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35
mozilla
CVE-2026-12305P3HIGHCVSS 7.5fixed in Firefox ESR 140.12
CVE-2026-12305 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12305
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12305
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2015-2725P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2725 [CRITICAL] CWE-119 CVE-2015-2725: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2024-6603P3HIGHCVSS 7.4≥ unspecified, < 115.132024-07-09
CVE-2024-6603 [HIGH] CWE-823 CVE-2024-6603: In an out-of-memory scenario an allocation could fail but free would have been called on the pointer
In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2018-12361P3HIGHCVSS 8.8fixed in 60.1≥ unspecified, < 60.12018-10-18
CVE-2018-12361 [HIGH] CWE-190 CVE-2018-12361: An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed
An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
nvd
CVE-2026-8947P3HIGHCVSS 7.3fixed in Firefox ESR 115.36
CVE-2026-8947 [HIGH] Mozilla Foundation Security Advisory 2026-47: CVE-2026-8947
Mozilla Foundation Security Advisory 2026-47
CVE: CVE-2026-8947
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.36
mozilla
CVE-2014-1562P3CRITICALCVSS 10.0v24.2v24.3+4 more2014-09-03
CVE-2014-1562 [CRITICAL] CWE-119 CVE-2014-1562: Unspecified vulnerability in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 24.x bef
Unspecified vulnerability in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before 31.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2026-8090P3HIGHCVSS 7.3fixed in Firefox ESR 115.35.2
CVE-2026-8090 [HIGH] Mozilla Foundation Security Advisory 2026-42: CVE-2026-8090
Mozilla Foundation Security Advisory 2026-42
CVE: CVE-2026-8090
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35.2
mozilla
CVE-2026-6752P3HIGHCVSS 7.3fixed in Firefox ESR 115.35
CVE-2026-6752 [HIGH] Mozilla Foundation Security Advisory 2026-31: CVE-2026-6752
Mozilla Foundation Security Advisory 2026-31
CVE: CVE-2026-6752
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35
mozilla
CVE-2026-12292P3UNKNOWNfixed in Firefox ESR 140.12
CVE-2026-12292 Mozilla Foundation Security Advisory 2026-58: CVE-2026-12292
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12292
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2019-17024P3HIGHCVSS 8.8fixed in 68.4vbefore 68.42020-01-08
CVE-2019-17024 [HIGH] CWE-787 CVE-2019-17024: Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of t
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2017-5436P3HIGHCVSS 8.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5436 [HIGH] CWE-787 CVE-2017-5436: An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font.
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2016-9905P3HIGHCVSS 8.8≥ unspecified, < 45.62018-06-11
CVE-2016-9905 [HIGH] CWE-284 CVE-2016-9905: A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. T
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
nvd
CVE-2018-5130P3HIGHCVSS 8.8≥ unspecified, < 52.72018-06-11
CVE-2018-5130 [HIGH] CWE-20 CVE-2018-5130: When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstance
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
nvd
CVE-2026-7323P3UNKNOWNfixed in Firefox ESR 140.10.1
CVE-2026-7323 Mozilla Foundation Security Advisory 2026-36: CVE-2026-7323
Mozilla Foundation Security Advisory 2026-36
CVE: CVE-2026-7323
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10.1
mozilla
CVE-2020-12419P3HIGHCVSS 8.8fixed in 68.10≥ unspecified, < 68.102020-07-09
CVE-2020-12419 [HIGH] CWE-416 CVE-2020-12419: When processing callbacks that occurred during window flushing in the parent process, the associated
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd