Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 29 of 45
CVE-2023-37208P3HIGHCVSS 7.8fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37208 [HIGH] CWE-434 CVE-2023-37208: When opening Diagcab files, Firefox did not warn the user that these files may contain malicious cod
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2019-11753P3HIGHCVSS 7.8≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11753 [HIGH] CWE-354 CVE-2019-11753: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenanc
nvd
CVE-2023-32214P3HIGHCVSS 7.5fixed in 102.11≥ unspecified, < 102.112023-06-19
CVE-2023-32214 [HIGH] CVE-2023-32214: Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of servic
Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service.
*Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2016-5296P3HIGHCVSS 7.5≥ unspecified, < 45.52018-06-11
CVE-2016-5296 [HIGH] CWE-119 CVE-2016-5296: A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulti
A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2018-5144P3HIGHCVSS 7.3≥ unspecified, < 52.72018-06-11
CVE-2018-5144 [HIGH] CWE-190 CVE-2018-5144: An integer overflow can occur during conversion of text to some Unicode character sets due to an unc
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
nvd
CVE-2017-5445P3HIGHCVSS 7.5≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5445 [HIGH] CWE-129 CVE-2017-5445: A vulnerability while parsing "application/http-index-format" format content where uninitialized val
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2022-42927P3HIGHCVSS 8.1fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42927 [HIGH] CWE-346 CVE-2022-42927: A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvd
CVE-2019-17010P3HIGHCVSS 7.5fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17010 [HIGH] CWE-362 CVE-2019-17010: Under certain conditions, when checking the Resist Fingerprinting preference during device orientati
Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2019-17011P3HIGHCVSS 7.5fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17011 [HIGH] CWE-362 CVE-2019-17011: Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a rac
Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2020-6821P3HIGHCVSS 7.5fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6821 [HIGH] CWE-908 CVE-2020-6821: When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSub
When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvd
CVE-2017-7760P3HIGHCVSS 7.8≥ unspecified, < 52.22018-06-11
CVE-2017-7760 [HIGH] CWE-417 CVE-2017-7760: The Mozilla Windows updater modifies some files to be updated by reading the original file and apply
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter through the Mozilla Maintenance Service, allowing the manipulation of files in the installation directory and privi
nvd
CVE-2018-12379P3HIGHCVSS 7.8≥ unspecified, < 60.22018-10-18
CVE-2018-12379 [HIGH] CWE-787 CVE-2018-12379: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2
nvd
CVE-2019-17009P3HIGHCVSS 7.8fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17009 [HIGH] CVE-2019-17009: When running, the updater service wrote status and log files to an unrestricted location; potentiall
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Th
nvd
CVE-2023-4048P3HIGHCVSS 7.5≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4048 [HIGH] CWE-125 CVE-2023-4048: An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2015-2708P4HIGHCVSS 7.5v31.1v31.2+4 more2015-05-14
CVE-2015-2708 [HIGH] CVE-2015-2708: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-0836P4HIGHCVSS 7.5v31.1v31.2+3 more2015-02-25
CVE-2015-0836 [HIGH] CVE-2015-0836: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2023-23599P3MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23599 [MEDIUM] CWE-116 CVE-2023-23599: When copying a network request from the developer tools panel as a curl command the output was not b
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
CVE-2014-8634P4HIGHCVSS 7.5v31.22015-01-14
CVE-2014-8634 [HIGH] CVE-2014-8634: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2026-6763P3MEDIUMCVSS 6.5fixed in Firefox ESR 140.10
CVE-2026-6763 [MEDIUM] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6763
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6763
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2016-9897P3HIGHCVSS 7.5fixed in 45.6≥ unspecified, < 45.62018-06-11
CVE-2016-9897 [HIGH] CWE-119 CVE-2016-9897: Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd