Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 32 of 49
CVE-2026-74981P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74981 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74981
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74981
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2016-5296P3HIGHCVSS 7.5≥ unspecified, < 45.52018-06-11
CVE-2016-5296 [HIGH] CWE-119 CVE-2016-5296: A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulti
A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2018-5144P3HIGHCVSS 7.3≥ unspecified, < 52.72018-06-11
CVE-2018-5144 [HIGH] CWE-190 CVE-2018-5144: An integer overflow can occur during conversion of text to some Unicode character sets due to an unc
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
nvd
CVE-2017-5445P3HIGHCVSS 7.5≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5445 [HIGH] CWE-129 CVE-2017-5445: A vulnerability while parsing "application/http-index-format" format content where uninitialized val
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arrays affected. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2022-42927P3HIGHCVSS 8.1fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42927 [HIGH] CWE-346 CVE-2022-42927: A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the
A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvd
CVE-2019-17010P3HIGHCVSS 7.5fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17010 [HIGH] CWE-362 CVE-2019-17010: Under certain conditions, when checking the Resist Fingerprinting preference during device orientati
Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
nvd
CVE-2017-7760P3HIGHCVSS 7.8≥ unspecified, < 52.22018-06-11
CVE-2017-7760 [HIGH] CWE-417 CVE-2017-7760: The Mozilla Windows updater modifies some files to be updated by reading the original file and apply
The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter through the Mozilla Maintenance Service, allowing the manipulation of files in the installation directory and privi
nvd
CVE-2018-12379P3HIGHCVSS 7.8≥ unspecified, < 60.22018-10-18
CVE-2018-12379 [HIGH] CWE-787 CVE-2018-12379: When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of
When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2
nvd
CVE-2019-17009P3HIGHCVSS 7.8fixed in 68.3vbefore 68.32020-01-08
CVE-2019-17009 [HIGH] CVE-2019-17009: When running, the updater service wrote status and log files to an unrestricted location; potentiall
When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Th
nvd
CVE-2023-4048P3HIGHCVSS 7.5≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4048 [HIGH] CWE-125 CVE-2023-4048: An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low
An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2026-74977P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74977 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74977
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74977
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2015-2708P4HIGHCVSS 7.5v31.1v31.2+4 more2015-05-14
CVE-2015-2708 [HIGH] CVE-2015-2708: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2015-0836P4HIGHCVSS 7.5v31.1v31.2+3 more2015-02-25
CVE-2015-0836 [HIGH] CVE-2015-0836: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2023-23599P3MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23599 [MEDIUM] CWE-116 CVE-2023-23599: When copying a network request from the developer tools panel as a curl command the output was not b
When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
CVE-2012-0459P4HIGHCVSS 7.5v10.1v10.22012-03-14
CVE-2012-0459 [HIGH] CWE-264 CVE-2012-0459: The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.
The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via dynamic modification of a keyframe
nvd
CVE-2014-8634P4HIGHCVSS 7.5v31.22015-01-14
CVE-2014-8634 [HIGH] CVE-2014-8634: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2026-6763P3MEDIUMCVSS 6.5fixed in Firefox ESR 140.10
CVE-2026-6763 [MEDIUM] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6763
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6763
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2016-9897P3HIGHCVSS 7.5fixed in 45.6≥ unspecified, < 45.62018-06-11
CVE-2016-9897 [HIGH] CWE-119 CVE-2016-9897: Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2019-11729P4HIGHCVSS 7.5≥ unspecified, < 60.82019-07-23
CVE-2019-11729 [HIGH] CWE-119 CVE-2019-11729: Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperl
Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2021-23981P3HIGHCVSS 8.1fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23981 [HIGH] CWE-787 CVE-2021-23981: A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buf
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
nvd