Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 27 of 49
CVE-2016-5290P3CRITICALCVSS 9.8≥ unspecified, < 45.52018-06-11
CVE-2016-5290 [CRITICAL] CWE-119 CVE-2016-5290: Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2018-5183P3CRITICALCVSS 9.8≥ unspecified, < 52.82018-06-11
CVE-2018-5183 [CRITICAL] CWE-119 CVE-2018-5183: Mozilla developers backported selected changes in the Skia library. These changes correct memory cor
Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerability affects Thunderbird ESR < 52.8, Thunderbird < 52.8, and Firefox ESR < 52.8.
nvd
CVE-2018-5145P3CRITICALCVSS 9.8≥ unspecified, < 52.72018-06-11
CVE-2018-5145 [CRITICAL] CWE-119 CVE-2018-5145: Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruptio
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
nvd
CVE-2017-7810P3CRITICALCVSS 9.8≥ unspecified, < 52.42018-06-11
CVE-2017-7810 [CRITICAL] CWE-119 CVE-2017-7810: Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2017-5454P3HIGHCVSS 7.5≥ unspecified, < 52.12018-06-11
CVE-2017-5454 [HIGH] CWE-200 CVE-2017-5454: A mechanism to bypass file system access protections in the sandbox to use the file picker to access
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2017-7779P3CRITICALCVSS 9.8≥ unspecified, < 52.32018-06-11
CVE-2017-7779 [CRITICAL] CWE-119 CVE-2017-7779: Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of thes
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2017-7793P3CRITICALCVSS 9.8≥ unspecified, < 52.42018-06-11
CVE-2017-7793 [CRITICAL] CWE-416 CVE-2017-7793: A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window a
A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
nvd
CVE-2017-5386P3HIGHCVSS 7.3≥ unspecified, < 45.72018-06-11
CVE-2017-5386 [HIGH] CVE-2017-5386: WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions usi
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensions. This vulnerability affects Firefox ESR < 45.7 and Firefox < 51.
nvd
CVE-2017-7758P3CRITICALCVSS 9.1≥ unspecified, < 52.22018-06-11
CVE-2017-7758 [CRITICAL] CWE-125 CVE-2017-7758: An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio st
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2024-3857P3HIGHCVSS 7.8≥ unspecified, < 115.102024-04-16
CVE-2024-3857 [HIGH] CWE-416 CVE-2024-3857: The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free
The JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2022-38476P3HIGHCVSS 7.5fixed in 102.2≥ unspecified, < 102.22022-12-22
CVE-2022-38476 [HIGH] CWE-416 CVE-2022-38476: A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-aft
A data race could occur in the PK11_ChangePW function, potentially leading to a use-after-free vulnerability. In Firefox, this lock protected the data when a user changed their master password. This vulnerability affects Firefox ESR < 102.2 and Thunderbird < 102.2.
nvd
CVE-2024-1552P3HIGHCVSS 7.5≥ unspecified, < 115.82024-02-20
CVE-2024-1552 [HIGH] CWE-681 CVE-2024-1552: Incorrect code generation could have led to unexpected numeric conversions and potential undefined b
Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2023-4051P3HIGHCVSS 7.5≥ unspecified, < 115.22023-08-01
CVE-2023-4051 [HIGH] CVE-2023-4051: A website could have obscured the full screen notification by using the file open dialog. This could
A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2022-26387P3HIGHCVSS 7.5fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26387 [HIGH] CWE-367 CVE-2022-26387: When installing an add-on, Firefox verified the signature before prompting the user; but while the u
When installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underlying add-on file could have been modified and Firefox would not have noticed. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvd
CVE-2022-22741P3HIGHCVSS 7.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22741 [HIGH] CVE-2022-22741: When resizing a popup while requesting fullscreen access, the popup would have become unable to leav
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-25743P3HIGHCVSS 7.5≥ unspecified, < 102.82023-06-02
CVE-2023-25743 [HIGH] CWE-290 CVE-2023-25743: A lack of in app notification for entering fullscreen mode could have lead to a malicious website sp
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
nvd
CVE-2024-8383P3HIGHCVSS 7.5fixed in 115.15≥ 128.0, < 128.2+2 more2024-09-03
CVE-2024-8383 [HIGH] CWE-1188 CVE-2024-8383: Firefox normally asks for confirmation before asking the operating system to find an application to
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user dow
nvd
CVE-2022-22759P3CRITICALCVSS 9.6fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22759 [CRITICAL] CWE-693 CVE-2022-22759: If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently append
If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2014-1547P3CRITICALCVSS 10.0v24.2v24.3+3 more2014-07-23
CVE-2014-1547 [CRITICAL] CVE-2014-1547: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2018-5125P3HIGHCVSS 8.8≥ unspecified, < 52.72018-06-11
CVE-2018-5125 [HIGH] CWE-119 CVE-2018-5125: Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evide
Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd