Mozilla Firefox Esr vulnerabilities

776 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
776
CISA KEV
9
actively exploited
Public exploits
17
Exploited in wild
13
Severity breakdown
CRITICAL186HIGH315MEDIUM269LOW6

Vulnerabilities

Page 3 of 39
CVE-2024-7519CRITICALCVSS 9.6fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7519 [CRITICAL] CWE-787 CVE-2024-7519: Insufficient checks when processing graphics shared memory could have led to memory corruption. This Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-7521HIGHCVSS 8.8fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7521 [HIGH] CWE-755 CVE-2024-7521: Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affe Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-7522HIGHCVSS 8.8fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7522 [HIGH] CWE-125 CVE-2024-7522: Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This v Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-7520HIGHCVSS 8.8fixed in 128.1.0≥ unspecified, < 128.12024-08-06
CVE-2024-7520 [HIGH] CWE-843 CVE-2024-7520: A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code ex A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
cvelistv5nvd
CVE-2024-7528HIGHCVSS 8.8fixed in 128.1.0≥ unspecified, < 128.12024-08-06
CVE-2024-7528 [HIGH] CWE-416 CVE-2024-7528: Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulne Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
cvelistv5nvd
CVE-2024-7527HIGHCVSS 8.8fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7527 [HIGH] CWE-416 CVE-2024-7527: Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerabil Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-7525HIGHCVSS 8.1fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7525 [HIGH] CWE-276 CVE-2024-7525: It was possible for a web extension with minimal permissions to create a `StreamFilter` which could It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-7531MEDIUMCVSS 6.5fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7531 [MEDIUM] CWE-367 CVE-2024-7531: Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can resu Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection per
cvelistv5nvd
CVE-2024-7526MEDIUMCVSS 6.5fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7526 [MEDIUM] CWE-908 CVE-2024-7526: ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-7529MEDIUMCVSS 6.5fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7529 [MEDIUM] CWE-451 CVE-2024-7529: The date picker could partially obscure security prompts. This could be used by a malicious site to The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
cvelistv5nvd
CVE-2024-7524MEDIUMCVSS 6.1fixed in 115.14≥ 116.0, < 128.1+2 more2024-08-06
CVE-2024-7524 [MEDIUM] CWE-79 CVE-2024-7524: Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. Thi
cvelistv5nvd
CVE-2024-7518MEDIUMCVSS 6.5fixed in 128.1≥ unspecified, < 128.12024-08-06
CVE-2024-7518 [MEDIUM] CWE-1021 CVE-2024-7518: Select options could obscure the fullscreen notification dialog. This could be used by a malicious s Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
cvelistv5nvd
CVE-2024-6602CRITICALCVSS 9.8≥ unspecified, < 115.132024-07-09
CVE-2024-6602 [CRITICAL] CWE-94 CVE-2024-6602: A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6603HIGHCVSS 7.4≥ unspecified, < 115.132024-07-09
CVE-2024-6603 [HIGH] CWE-823 CVE-2024-6603: In an out-of-memory scenario an allocation could fail but free would have been called on the pointer In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6604HIGHCVSS 7.5≥ unspecified, < 115.132024-07-09
CVE-2024-6604 [HIGH] CWE-120 CVE-2024-6604: Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these Memory safety bugs present in Firefox 127, Firefox ESR 115.12, and Thunderbird 115.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6601MEDIUMCVSS 4.7≥ unspecified, < 115.132024-07-09
CVE-2024-6601 [MEDIUM] CWE-367 CVE-2024-6601: A race condition could lead to a cross-origin container obtaining permissions of the top-level origi A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvd
CVE-2024-6600MEDIUMCVSS 6.3≥ unspecified, < 115.132024-07-09
CVE-2024-6600 [MEDIUM] CWE-770 CVE-2024-6600: Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access c Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
cvelistv5nvd
CVE-2024-5696HIGHCVSS 8.6≥ unspecified, < 115.122024-06-11
CVE-2024-5696 [HIGH] CWE-787 CVE-2024-5696: By manipulating the text in an `&lt;input&gt;` tag, an attacker could have caused corrupt memory lea By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
cvelistv5nvd
CVE-2024-5702HIGHCVSS 7.5≥ unspecified, < 115.122024-06-11
CVE-2024-5702 [HIGH] CWE-416 CVE-2024-5702: Memory corruption in the networking stack could have led to a potentially exploitable crash. This vu Memory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, Firefox ESR < 115.12, and Thunderbird < 115.12.
cvelistv5nvd
CVE-2024-5688HIGHCVSS 8.1≥ unspecified, < 115.122024-06-11
CVE-2024-5688 [HIGH] CWE-416 CVE-2024-5688: If a garbage collection was triggered at the right time, a use-after-free could have occurred during If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
cvelistv5nvd