cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 30 of 49
CVE-2023-4052P3MEDIUMCVSS 6.5fixed in 115.1≥ unspecified, < 115.12023-08-01
CVE-2023-4052 [MEDIUM] CWE-59 CVE-2023-4052: The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privilege
nvd
CVE-2017-5410P3CRITICALCVSS 9.8≥ unspecified, < 45.82018-06-11
CVE-2017-5410 [CRITICAL] CWE-119 CVE-2017-5410: Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScri Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-7805P3HIGHCVSS 7.5≥ unspecified, < 52.42018-06-11
CVE-2017-7805 [HIGH] CWE-416 CVE-2017-7805: During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-fr
nvd
CVE-2017-7787P3HIGHCVSS 7.5fixed in 52.3≥ unspecified, < 52.32018-06-11
CVE-2017-7787 [HIGH] CWE-200 CVE-2017-7787: Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, a Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2016-9893P3CRITICALCVSS 9.8≥ unspecified, < 45.62018-06-11
CVE-2016-9893 [CRITICAL] CWE-119 CVE-2016-9893: Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory c Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-5464P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5464 [CRITICAL] CWE-119 CVE-2017-5464: During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sy During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2018-5157P3HIGHCVSS 7.5≥ unspecified, < 52.82018-06-11
CVE-2018-5157 [HIGH] CWE-200 CVE-2018-5157: Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept m Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
nvd
CVE-2021-38498P3HIGHCVSS 7.5fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38498 [HIGH] CWE-416 CVE-2021-38498: During process shutdown, a document could have caused a use-after-free of a languages service object During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvd
CVE-2023-5728P3HIGHCVSS 7.5fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5728 [HIGH] CWE-416 CVE-2023-5728: During garbage collection extra operations were performed on a object that should not be. This could During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2026-6776P3HIGHCVSS 7.8fixed in Firefox ESR 140.10
CVE-2026-6776 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6776 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6776 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2022-22737P3HIGHCVSS 7.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22737 [HIGH] CWE-362 CVE-2022-22737: Constructing audio sinks could have lead to a race condition when playing audio files and closing wi Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2024-7652P3HIGHCVSS 7.5≥ unspecified, < 115.132024-09-06
CVE-2024-7652 [HIGH] CWE-476 CVE-2024-7652: An error in the ECMA-262 specification relating to Async Generators could have resulted in a type co An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2024-9399P3HIGHCVSS 7.5≥ unspecified, < 128.32024-10-01
CVE-2024-9399 [HIGH] CWE-404 CVE-2024-9399: A website configured to initiate a specially crafted WebTransport session could crash the Firefox pr A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2022-22753P3HIGHCVSS 7.1fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22753 [HIGH] CWE-367 CVE-2022-22753: A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6,
nvd
CVE-2026-16391P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16391 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16391 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16391 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16374P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16374 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16374 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16374 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-74958P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74958 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74958 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74958 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-84130P3UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84130 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84130 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84130 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2026-74954P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74954 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74954 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74954 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74960P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74960 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74960 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74960 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
Mozilla Firefox Esr vulnerabilities | cvebase