cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 29 of 49
CVE-2019-11694P3HIGHCVSS 7.5≥ unspecified, < 60.72019-07-23
CVE-2019-11694 [HIGH] CWE-755 CVE-2019-11694: A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked t A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information stored at that memory location. *Note: this issue only occurs on Windows. Other operating systems are unaffected.
nvd
CVE-2024-0743P3HIGHCVSS 7.5≥ unspecified, < 115.92024-01-23
CVE-2024-0743 [HIGH] CWE-252 CVE-2024-0743: An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. T An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2024-5702P3HIGHCVSS 7.5≥ unspecified, < 115.122024-06-11
CVE-2024-5702 [HIGH] CWE-416 CVE-2024-5702: Memory corruption in the networking stack could have led to a potentially exploitable crash. This vu Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2023-4055P3HIGHCVSS 7.5≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4055 [HIGH] CWE-120 CVE-2023-4055: When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2024-1546P3HIGHCVSS 7.5≥ unspecified, < 115.82024-02-20
CVE-2024-1546 [HIGH] CWE-125 CVE-2024-1546: When storing and re-accessing data on a networking channel, the length of buffers may have been conf When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2022-36319P3HIGHCVSS 7.5fixed in 102.1fixed in 91.12+2 more2022-12-22
CVE-2022-36319 [HIGH] CWE-1021 CVE-2022-36319: When combining CSS properties for overflow and transform, the mouse cursor could interact with diffe When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
nvd
CVE-2023-4583P3HIGHCVSS 7.5fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4583 [HIGH] CWE-754 CVE-2023-4583: When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2024-10458P3HIGHCVSS 7.5≥ unspecified, < 128.4≥ unspecified, < 115.172024-10-29
CVE-2024-10458 [HIGH] CWE-281 CVE-2024-10458: A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `objec A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-8968P3HIGHCVSS 7.5fixed in Firefox ESR 140.11
CVE-2026-8968 [HIGH] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8968 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8968 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2019-9812P3CRITICALCVSS 9.3vbefore 60.9vbefore 68.12020-01-08
CVE-2019-9812 [CRITICAL] CVE-2019-9812: Given a compromised sandboxed content process due to a separate vulnerability, it is possible to esc Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart withou
nvd
CVE-2026-16354P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16354 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16354 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16354 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-6753P3UNKNOWNfixed in Firefox ESR 140.10
CVE-2026-6753 Mozilla Foundation Security Advisory 2026-32: CVE-2026-6753 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6753 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-84132P3UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84132 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84132 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84132 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2026-84144P3UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84144 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84144 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84144 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2026-74978P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74978 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74978 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74978 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2014-1538P3CRITICALCVSS 10.0v24.2v24.3+2 more2014-06-11
CVE-2014-1538 [CRITICAL] CVE-2014-1538: Use-after-free vulnerability in the nsTextEditRules::CreateMozBR function in Mozilla Firefox before Use-after-free vulnerability in the nsTextEditRules::CreateMozBR function in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors.
nvd
CVE-2018-12364P3HIGHCVSS 8.8fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12364 [HIGH] CWE-352 CVE-2018-12364: NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by mak NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR
nvd
CVE-2018-12371P3HIGHCVSS 8.8≥ unspecified, < 60.12020-07-09
CVE-2018-12371 [HIGH] CWE-190 CVE-2018-12371: An integer overflow vulnerability in the Skia library when allocating memory for edge builders on so An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. This results in the use of uninitialized memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.1, Thunderbird < 60, and Firefox < 61.
nvd
CVE-2019-9811P3HIGHCVSS 8.3fixed in 60.8≥ unspecified, < 60.82019-07-23
CVE-2019-9811 [HIGH] CWE-74 CVE-2019-9811: As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malic As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2021-43535P3HIGHCVSS 8.8fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-43535 [HIGH] CWE-416 CVE-2021-43535: A use-after-free could have occured when an HTTP2 session object was released on a different thread, A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase