cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 3 of 45
CVE-2026-16359P3CRITICALCVSS 9.1fixed in Firefox ESR 115.38
CVE-2026-16359 [CRITICAL] Mozilla Foundation Security Advisory 2026-69: CVE-2026-16359 Mozilla Foundation Security Advisory 2026-69 CVE: CVE-2026-16359 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.38
mozilla
CVE-2026-12315P3CRITICALCVSS 9.1fixed in Firefox ESR 140.12
CVE-2026-12315 [CRITICAL] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12315 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12315 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12304P3CRITICALCVSS 9.1fixed in Firefox ESR 140.12
CVE-2026-12304 [CRITICAL] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12304 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12304 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2019-9794P3CRITICALCVSS 9.8≥ unspecified, < 60.62019-04-26
CVE-2019-9794 [CRITICAL] CWE-88 CVE-2019-9794: A vulnerability was discovered where specific command line arguments are not properly discarded duri A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command line arguments if Firefox is configured as the default URI handler for a given URI scheme in third part
nvd
CVE-2026-16383P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16383 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16383 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16383 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16360P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16360 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16360 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16360 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16349P3UNKNOWNfixed in Firefox ESR 115.38
CVE-2026-16349 Mozilla Foundation Security Advisory 2026-69: CVE-2026-16349 Mozilla Foundation Security Advisory 2026-69 CVE: CVE-2026-16349 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.38
mozilla
CVE-2020-12388P3CRITICALCVSS 10.0fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12388 [CRITICAL] CWE-20 CVE-2020-12388: The Firefox content processes did not sufficiently lockdown access control which could result in a s The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
nvd
CVE-2020-12389P3CRITICALCVSS 10.0fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12389 [CRITICAL] CWE-20 CVE-2020-12389: The Firefox content processes did not sufficiently lockdown access control which could result in a s The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.
nvd
CVE-2024-9392P3CRITICALCVSS 9.8≥ unspecified, < 128.3≥ unspecified, < 115.162024-10-01
CVE-2024-9392 [CRITICAL] CWE-346 CVE-2024-9392: A compromised content process could have allowed for the arbitrary loading of cross-origin pages. Th A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2020-15663P3HIGHCVSS 8.8≥ 68.0, < 68.12≥ unspecified, < 68.12+1 more2020-10-01
CVE-2020-15663 [HIGH] CWE-427 CVE-2020-15663: If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location with system privileges. Although the Mozilla Maintenance Service does ensure that updater.exe is signed by Mozilla, the version could have been rolled back to a previous version which would have allowed exploitation
nvd
CVE-2026-16352P3UNKNOWNfixed in Firefox ESR 115.38
CVE-2026-16352 Mozilla Foundation Security Advisory 2026-69: CVE-2026-16352 Mozilla Foundation Security Advisory 2026-69 CVE: CVE-2026-16352 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.38
mozilla
CVE-2026-16351P3UNKNOWNfixed in Firefox ESR 115.38
CVE-2026-16351 Mozilla Foundation Security Advisory 2026-69: CVE-2026-16351 Mozilla Foundation Security Advisory 2026-69 CVE: CVE-2026-16351 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.38
mozilla
CVE-2026-16356P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16356 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16356 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16356 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16377P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16377 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16377 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16377 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2024-29944P3HIGHCVSS 8.4≥ unspecified, < 115.9.12024-03-22
CVE-2024-29944 [HIGH] CWE-830 CVE-2024-29944: An attacker was able to inject an event handler into a privileged object that would allow arbitrary An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.
nvd
CVE-2023-5168P3CRITICALCVSS 9.8fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5168 [CRITICAL] CWE-787 CVE-2023-5168: A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbir
nvd
CVE-2018-18500P3CRITICALCVSS 9.8fixed in 60.52019-02-05
CVE-2018-18500 [CRITICAL] CWE-416 CVE-2018-18500: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML e A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
nvd
CVE-2026-8956P3CRITICALCVSS 9.8fixed in Firefox ESR 140.11
CVE-2026-8956 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8956 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8956 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2024-8385P3CRITICALCVSS 9.8fixed in 128.2≥ unspecified, < 128.22024-09-03
CVE-2024-8385 [CRITICAL] CWE-843 CVE-2024-8385: A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an expl A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase