cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 31 of 49
CVE-2026-74962P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74962 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74962 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74962 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2021-29951P3MEDIUMCVSS 6.5fixed in 78.10.1≥ unspecified, < 78.10.12021-06-24
CVE-2021-29951 [MEDIUM] CWE-269 CVE-2021-29951: The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain net The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an attacker spammed the 'Stop' command); but also exposed attack surface in the maintenance service. *Not
nvd
CVE-2019-11712P3HIGHCVSS 8.8≥ unspecified, < 60.82019-07-23
CVE-2019-11712 [HIGH] CWE-352 CVE-2019-11712: POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2015-2728P3HIGHCVSS 7.5v31.1v31.2+5 more2015-07-06
CVE-2015-2728 [HIGH] CVE-2015-2728: The IndexedDatabaseManager class in the IndexedDB implementation in Mozilla Firefox before 39.0 and The IndexedDatabaseManager class in the IndexedDB implementation in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 misinterprets an unspecified IDBDatabase field as a pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors, r
nvd
CVE-2017-7807P3HIGHCVSS 8.1≥ unspecified, < 52.32018-06-11
CVE-2017-7807 [HIGH] CWE-20 CVE-2017-7807: A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2016-9904P3HIGHCVSS 7.5≥ unspecified, < 45.62018-06-11
CVE-2016-9904 [HIGH] CWE-200 CVE-2016-9904: An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by ano An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-7754P3HIGHCVSS 7.5≥ unspecified, < 52.22018-06-11
CVE-2017-7754 [HIGH] CWE-125 CVE-2017-7754: An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations An out-of-bounds read in WebGL with a maliciously crafted "ImageInfo" object during WebGL operations. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2017-7803P3HIGHCVSS 7.5≥ unspecified, < 52.32018-06-11
CVE-2017-7803 [HIGH] CWE-269 CVE-2017-7803: When a page's content security policy (CSP) header contains a "sandbox" directive, other directives When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2015-0817P3MEDIUMCVSS 6.8v31.1v31.2+3 more2015-03-24
CVE-2015-0817 [MEDIUM] CWE-17 CVE-2015-0817: The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaM The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 does not properly determine the cases in which bounds checking may be safely skipped during JIT compilation and heap access, which allows remote attackers to read or write to unintended memory locations, and consequently execute arbit
nvd
CVE-2019-17011P3HIGHCVSS 7.5fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17011 [HIGH] CWE-362 CVE-2019-17011: Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a rac Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2020-6821P3HIGHCVSS 7.5fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6821 [HIGH] CWE-908 CVE-2020-6821: When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSub When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvd
CVE-2017-7765P3HIGHCVSS 7.5≥ unspecified, < 52.22018-06-11
CVE-2017-7765 [HIGH] CWE-20 CVE-2017-7765: The "Mark of the Web" was not correctly saved on Windows when files with very long names were downlo The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, the security warning that Windows displays before running executables downloaded from the Internet is not shown. Note: This attack only affects Windows operating systems. Other operating systems are
nvd
CVE-2016-9902P3HIGHCVSS 7.5≥ unspecified, < 45.62018-06-11
CVE-2016-9902 [HIGH] CWE-346 CVE-2016-9902: The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 a
nvd
CVE-2017-7766P3HIGHCVSS 7.8≥ unspecified, < 52.22018-06-11
CVE-2017-7766 [HIGH] CVE-2017-7766: An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and pri An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems
nvd
CVE-2023-37208P3HIGHCVSS 7.8fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37208 [HIGH] CWE-434 CVE-2023-37208: When opening Diagcab files, Firefox did not warn the user that these files may contain malicious cod When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2019-11753P3HIGHCVSS 7.8≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11753 [HIGH] CWE-354 CVE-2019-11753: The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location and the updated maintenance service in the unprotected location has been altered, the altered maintenanc
nvd
CVE-2023-32214P3HIGHCVSS 7.5fixed in 102.11≥ unspecified, < 102.112023-06-19
CVE-2023-32214 [HIGH] CVE-2023-32214: Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of servic Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2026-74982P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74982 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74982 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74982 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74966P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74966 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74966 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74966 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74934P3UNKNOWNfixed in Firefox ESR 140.14
CVE-2026-74934 Mozilla Foundation Security Advisory 2026-76: CVE-2026-74934 Mozilla Foundation Security Advisory 2026-76 CVE: CVE-2026-74934 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.14
mozilla
Mozilla Firefox Esr vulnerabilities | cvebase