Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 31 of 45
CVE-2017-7814P4HIGHCVSS 7.8≥ unspecified, < 52.42018-06-11
CVE-2017-7814 [HIGH] CWE-20 CVE-2017-7814: File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks th
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firef
nvd
CVE-2018-12365P4MEDIUMCVSS 6.5fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12365 [MEDIUM] CWE-200 CVE-2018-12365: A compromised IPC child process can escape the content sandbox and list the names of arbitrary files
A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2014-8639P4MEDIUMCVSS 6.8v31.22015-01-14
CVE-2014-8639 [MEDIUM] CVE-2014-8639: Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey be
Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to th
nvd
CVE-2023-6209P4MEDIUMCVSS 6.5fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6209 [MEDIUM] CWE-22 CVE-2023-6209: Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2020-26965P4MEDIUMCVSS 6.5fixed in 78.52020-12-09
CVE-2020-26965 [MEDIUM] CWE-212 CVE-2020-26965: Some websites have a feature "Show Password" where clicking a button will change a password field in
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and t
nvd
CVE-2023-6865P4MEDIUMCVSS 6.5fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6865 [MEDIUM] CVE-2023-6865: `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be a
`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
nvd
CVE-2023-37207P4MEDIUMCVSS 6.5fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37207 [MEDIUM] CWE-470 CVE-2023-37207: A website could have obscured the fullscreen notification by using a URL with a scheme handled by an
A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2024-5692P4MEDIUMCVSS 6.5≥ unspecified, < 115.122024-06-11
CVE-2024-5692 [MEDIUM] CVE-2024-5692: On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser in
On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firef
nvd
CVE-2012-0454P4HIGHCVSS 7.5v10.1v10.22012-03-14
CVE-2012-0454 [HIGH] CWE-399 CVE-2012-0454: Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Th
Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 on 32-bit Windows 7 platforms allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving use of
nvd
CVE-2018-12396P4MEDIUMCVSS 6.5fixed in 60.3≥ unspecified, < 60.32019-02-28
CVE-2018-12396 [MEDIUM] CWE-732 CVE-2018-12396: A vulnerability where a WebExtension can run content scripts in disallowed contexts following naviga
A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
nvd
CVE-2024-5700P4HIGHCVSS 7.0≥ unspecified, < 115.122024-06-11
CVE-2024-5700 [HIGH] CWE-786 CVE-2024-5700: Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these
Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2021-38505P4MEDIUMCVSS 6.5fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38505 [MEDIUM] CWE-668 CVE-2021-38505: Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will re
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before v
nvd
CVE-2023-5169P4MEDIUMCVSS 6.5fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5169 [MEDIUM] CWE-787 CVE-2023-5169: A compromised content process could have provided malicious data in a `PathRecording` resulting in a
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2023-5732P4MEDIUMCVSS 6.5fixed in 115.4.1≥ unspecified, < 115.42023-10-25
CVE-2023-5732 [MEDIUM] CVE-2023-5732: An attacker could have created a malicious link using bidirectional characters to spoof the location
An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-5727P4MEDIUMCVSS 6.5fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5727 [MEDIUM] CVE-2023-5727: The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxb
The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer.
*Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-4053P4MEDIUMCVSS 6.5≥ unspecified, < 115.22023-08-01
CVE-2023-4053 [MEDIUM] CWE-59 CVE-2023-4053: A website could have obscured the full screen notification by using a URL with a scheme handled by a
A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2022-45410P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45410 [MEDIUM] CWE-862 CVE-2022-45410: When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request w
When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2021-23982P4MEDIUMCVSS 6.5fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23982 [MEDIUM] CWE-326 CVE-2021-23982: Using techniques that built on the slipstream research, a malicious webpage could have scanned both
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
nvd
CVE-2024-0753P4MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0753 [MEDIUM] CVE-2024-0753: In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerabil
In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2022-45408P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45408 [MEDIUM] CWE-79 CVE-2022-45408: Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen wi
Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd