cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 33 of 45
CVE-2018-12397P4HIGHCVSS 7.1≥ unspecified, < 60.32019-02-28
CVE-2018-12397 [HIGH] CWE-200 CVE-2018-12397: A WebExtension can request access to local files without the warning prompt stating that the extensi A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63
nvd
CVE-2020-12421P4MEDIUMCVSS 6.5fixed in 68.10.0≥ unspecified, < 68.102020-07-09
CVE-2020-12421 [MEDIUM] CWE-295 CVE-2020-12421: When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected ( When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2021-43542P4MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43542 [MEDIUM] CWE-209 CVE-2021-43542: Using XMLHttpRequest, an attacker could have identified installed applications by probing error mess Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2021-43541P4MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43541 [MEDIUM] CVE-2021-43541: When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces w When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-15655P4MEDIUMCVSS 6.5fixed in 78.1≥ unspecified, < 78.12020-08-10
CVE-2020-15655 [MEDIUM] CVE-2020-15655: A redirected HTTP request which is observed or modified through a web extension could bypass existin A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential disclosure of cross-origin information. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2020-15664P4MEDIUMCVSS 6.5fixed in 68.12≥ unspecified, < 68.12+1 more2020-10-01
CVE-2020-15664 [MEDIUM] CWE-863 CVE-2020-15664: By holding a reference to the eval() function from an about:blank window, a malicious webpage could By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed. This vulnerability affects Firef
nvd
CVE-2020-26966P4MEDIUMCVSS 6.5fixed in 78.52020-12-09
CVE-2020-26966 [MEDIUM] CVE-2020-26966: Searching for a single word from the address bar caused an mDNS request to be sent on the local netw Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thu
nvd
CVE-2022-40959P4MEDIUMCVSS 6.5fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40959 [MEDIUM] CWE-922 CVE-2022-40959: During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading t During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2020-15653P4MEDIUMCVSS 6.5fixed in 78.1≥ unspecified, < 78.12020-08-10
CVE-2020-15653 [MEDIUM] CVE-2020-15653: An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. Th An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed popups and hosted arbitrary content. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2023-6860P4MEDIUMCVSS 6.5fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6860 [MEDIUM] CVE-2023-6860: The `VideoBridge` allowed any content process to use textures produced by remote decoders. This cou The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2023-6204P4MEDIUMCVSS 6.5fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6204 [MEDIUM] CWE-125 CVE-2023-6204: On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bo On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2021-38507P4MEDIUMCVSS 6.5fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38507 [MEDIUM] CWE-346 CVE-2021-38507: The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upg The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted connections on port 80. However, if a second encrypted port on the same IP address (e.g. port 8443) did not opt-in to opportunistic
nvd
CVE-2022-28285P4MEDIUMCVSS 6.5fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28285 [MEDIUM] CWE-125 CVE-2022-28285: When generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet When generating the assembly code for MLoadTypedArrayElementHole, an incorrect AliasSet was used. In conjunction with another vulnerability this could have been used for an out of bounds memory read. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvd
CVE-2022-34479P4MEDIUMCVSS 6.5fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-34479 [MEDIUM] CWE-451 CVE-2022-34479: A malicious website that could create a popup could have resized the popup to overlay the address ba A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. *This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102
nvd
CVE-2024-10463P4MEDIUMCVSS 6.5≥ unspecified, < 128.4≥ unspecified, < 115.172024-10-29
CVE-2024-10463 [MEDIUM] CWE-203 CVE-2024-10463: Video frames could have been leaked between origins in some situations. This vulnerability affects F Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2023-29548P4MEDIUMCVSS 6.5fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29548 [MEDIUM] CVE-2023-29548: A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvd
CVE-2022-22739P4MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22739 [MEDIUM] CVE-2022-22739: Malicious websites could have tricked users into accepting launching a program to handle an external Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-25728P4MEDIUMCVSS 6.5fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25728 [MEDIUM] CWE-203 CVE-2023-25728: The <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child The Content-Security-Policy-Report-Only header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2022-22754P4MEDIUMCVSS 6.5fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22754 [MEDIUM] CWE-863 CVE-2022-22754: If a user installed an extension of a particular type, the extension could have auto-updated itself If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2023-4577P4MEDIUMCVSS 6.5fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4577 [MEDIUM] CVE-2023-4577: When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbag When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase