Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 34 of 45
CVE-2023-23603P4MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23603 [MEDIUM] CWE-770 CVE-2023-23603: Regular expressions used to filter out forbidden properties and values from style directives in call
Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
CVE-2023-4573P4MEDIUMCVSS 6.5fixed in 102.15≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4573 [MEDIUM] CWE-416 CVE-2023-4573: When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which c
When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
nvd
CVE-2022-45404P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45404 [MEDIUM] CWE-451 CVE-2022-45404: Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to g
Through a series of popup and window.print() calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2023-23602P4MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23602 [MEDIUM] CWE-754 CVE-2023-23602: A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Pol
A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
CVE-2024-10464P4MEDIUMCVSS 6.5≥ unspecified, < 128.42024-10-29
CVE-2024-10464 [MEDIUM] CWE-125 CVE-2024-10464: Repeated writes to history interface attributes could have been used to cause a Denial of Service co
Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2024-0747P4MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0747 [MEDIUM] CWE-693 CVE-2024-0747: When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Pol
When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2023-29545P4MEDIUMCVSS 6.5fixed in 102.102023-06-19
CVE-2023-29545 [MEDIUM] CVE-2023-29545: Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing en
Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user.
*This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR
nvd
CVE-2024-7526P4MEDIUMCVSS 6.5fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7526 [MEDIUM] CWE-908 CVE-2024-7526: ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be
ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2024-7518P4MEDIUMCVSS 6.5fixed in 128.1≥ unspecified, < 128.12024-08-06
CVE-2024-7518 [MEDIUM] CWE-1021 CVE-2024-7518: Select options could obscure the fullscreen notification dialog. This could be used by a malicious s
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
nvd
CVE-2022-38472P4MEDIUMCVSS 6.5≥ unspecified, < 91.13≥ unspecified, < 102.22022-12-22
CVE-2022-38472 [MEDIUM] CWE-346 CVE-2022-38472: An attacker could have abused XSLT error handling to associate attacker-controlled content with anot
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR <
nvd
CVE-2026-12325P4MEDIUMCVSS 6.5fixed in Firefox ESR 115.37
CVE-2026-12325 [MEDIUM] Mozilla Foundation Security Advisory 2026-59: CVE-2026-12325
Mozilla Foundation Security Advisory 2026-59
CVE: CVE-2026-12325
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.37
mozilla
CVE-2019-9793P4MEDIUMCVSS 5.9fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9793 [MEDIUM] CWE-119 CVE-2019-9793: A mechanism was discovered that removes some bounds checking for string, array, or typed array acces
A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have
nvd
CVE-2018-12366P4MEDIUMCVSS 6.5fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12366 [MEDIUM] CWE-125 CVE-2018-12366: An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds rea
An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
nvd
CVE-2017-7830P4MEDIUMCVSS 6.5≥ unspecified, < 52.52018-06-11
CVE-2017-7830 [MEDIUM] CVE-2017-7830: The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-ori
The Resource Timing API incorrectly revealed navigations in cross-origin iframes. This is a same-origin policy violation and could allow for data theft of URLs loaded by users. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvd
CVE-2026-8961P4UNKNOWNfixed in Firefox ESR 140.11
CVE-2026-8961 Mozilla Foundation Security Advisory 2026-48: CVE-2026-8961
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8961
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-6757P4UNKNOWNfixed in Firefox ESR 140.10
CVE-2026-6757 Mozilla Foundation Security Advisory 2026-32: CVE-2026-6757
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6757
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2019-11742P4MEDIUMCVSS 6.5≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11742 [MEDIUM] CWE-829 CVE-2019-11742: A same-origin policy violation occurs allowing the theft of cross-origin images through a combinatio
A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a element due to an error in how same-origin policy is applied to cached image content. The resulting same-origin policy violation could allow for data theft. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbir
nvd
CVE-2021-43536P4MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43536 [MEDIUM] CWE-200 CVE-2021-43536: Under certain circumstances, asynchronous functions could have caused a navigation to fail but expos
Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2018-12385P4HIGHCVSS 7.0fixed in 60.2.1≥ unspecified, < 60.2.12018-10-18
CVE-2018-12385 [HIGH] CWE-20 CVE-2018-12385: A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data store
A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploit
nvd
CVE-2020-15658P4MEDIUMCVSS 6.5fixed in 78.1≥ unspecified, < 78.12020-08-10
CVE-2020-15658 [MEDIUM] CWE-754 CVE-2020-15658: The code for downloading files did not properly take care of special characters, which led to an att
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd