Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 24 of 45
CVE-2026-7322P3UNKNOWNfixed in Firefox ESR 115.35.1
CVE-2026-7322 Mozilla Foundation Security Advisory 2026-37: CVE-2026-7322
Mozilla Foundation Security Advisory 2026-37
CVE: CVE-2026-7322
Product: Firefox ESR
Impact: critical
Fixed in: Firefox ESR 115.35.1
mozilla
CVE-2019-17005P3HIGHCVSS 8.8fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17005 [HIGH] CWE-787 CVE-2019-17005: The plain text serializer used a fixed-size array for the number of <ol> elements it could process;
The plain text serializer used a fixed-size array for the number of elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2019-17015P3HIGHCVSS 8.8fixed in 68.4vbefore 68.42020-01-08
CVE-2019-17015 [HIGH] CWE-787 CVE-2019-17015: During the initialization of a new content process, a pointer offset can be manipulated leading to m
During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploitable crash in the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2021-29980P3HIGHCVSS 8.8fixed in 78.13.0≥ unspecified, < 78.132021-08-17
CVE-2021-29980 [HIGH] CWE-909 CVE-2021-29980: Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corr
Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Thunderbird < 91, Firefox ESR < 78.13, and Firefox < 91.
nvd
CVE-2020-35112P3HIGHCVSS 8.8fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-35112 [HIGH] CVE-2020-35112: If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the download
If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other ope
nvd
CVE-2021-38495P3HIGHCVSS 8.8fixed in 91.1≥ unspecified, < 91.12021-11-03
CVE-2021-38495 [HIGH] CWE-787 CVE-2021-38495: Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs sh
Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 91.1 and Firefox ESR < 91.1.
nvd
CVE-2022-22738P3HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22738 [HIGH] CWE-787 CVE-2022-22738: Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a hea
Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2022-34468P3HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-34468 [HIGH] CWE-829 CVE-2022-34468: An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascrip
An iframe that was not permitted to run scripts could do so if the user clicked on a javascript: link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2014-8641P3HIGHCVSS 7.5v31.22015-01-14
CVE-2014-8641 [HIGH] CVE-2014-8641: Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ES
Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, and SeaMonkey before 2.32 allows remote attackers to execute arbitrary code via crafted track data.
nvd
CVE-2022-29909P3HIGHCVSS 8.8fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29909 [HIGH] CWE-276 CVE-2022-29909: Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to
Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2022-45412P3HIGHCVSS 8.8fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45412 [HIGH] CWE-59 CVE-2022-45412: When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produc
When resolving a symlink such as file:///proc/self/fd/1, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. *This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird
nvd
CVE-2022-34481P3HIGHCVSS 8.8fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-34481 [HIGH] CWE-190 CVE-2022-34481: In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occu
In the nsTArray_Impl::ReplaceElementsAt() function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2023-32213P3HIGHCVSS 8.8fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32213 [HIGH] CWE-908 CVE-2023-32213: When reading a file, an uninitialized value could have been used as read limit. This vulnerability a
When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2014-1541P3CRITICALCVSS 10.0v24.2v24.3+2 more2014-06-11
CVE-2014-1541 [CRITICAL] CVE-2014-1541: Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Co
Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Controller in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted web content.
nvd
CVE-2022-46881P3HIGHCVSS 8.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46881 [HIGH] CWE-787 CVE-2022-46881: An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash.
*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106, Firefox ESR <
nvd
CVE-2022-31741P3HIGHCVSS 8.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31741 [HIGH] CWE-908 CVE-2022-31741: A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and
A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2015-2710P3MEDIUMCVSS 6.8v31.1v31.2+4 more2015-05-14
CVE-2015-2710 [MEDIUM] CWE-119 CVE-2015-2710: Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.
Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
nvd
CVE-2017-5373P3CRITICALCVSS 9.8≥ unspecified, < 45.72018-06-11
CVE-2017-5373 [CRITICAL] CWE-119 CVE-2017-5373: Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evi
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2016-5290P3CRITICALCVSS 9.8≥ unspecified, < 45.52018-06-11
CVE-2016-5290 [CRITICAL] CWE-119 CVE-2016-5290: Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2018-5183P3CRITICALCVSS 9.8≥ unspecified, < 52.82018-06-11
CVE-2018-5183 [CRITICAL] CWE-119 CVE-2018-5183: Mozilla developers backported selected changes in the Skia library. These changes correct memory cor
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
nvd