cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 34 of 49
CVE-2023-6209P4MEDIUMCVSS 6.5fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6209 [MEDIUM] CWE-22 CVE-2023-6209: Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2020-26965P4MEDIUMCVSS 6.5fixed in 78.52020-12-09
CVE-2020-26965 [MEDIUM] CWE-212 CVE-2020-26965: Some websites have a feature "Show Password" where clicking a button will change a password field in Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used that feature, the type of the password field was changed, resulting in a keyboard layout change and t
nvd
CVE-2023-37207P4MEDIUMCVSS 6.5fixed in 102.13≥ unspecified, < 102.132023-07-05
CVE-2023-37207 [MEDIUM] CWE-470 CVE-2023-37207: A website could have obscured the fullscreen notification by using a URL with a scheme handled by an A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
nvd
CVE-2012-0454P4HIGHCVSS 7.5v10.1v10.22012-03-14
CVE-2012-0454 [HIGH] CWE-399 CVE-2012-0454: Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Th Use-after-free vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 on 32-bit Windows 7 platforms allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving use of
nvd
CVE-2020-12418P4MEDIUMCVSS 6.5fixed in 68.10≥ unspecified, < 68.102020-07-09
CVE-2020-12418 [MEDIUM] CWE-125 CVE-2020-12418: Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking proce Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2024-5700P4HIGHCVSS 7.0≥ unspecified, < 115.122024-06-11
CVE-2024-5700 [HIGH] CWE-786 CVE-2024-5700: Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these Memory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2021-38505P4MEDIUMCVSS 6.5fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38505 [MEDIUM] CWE-668 CVE-2021-38505: Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will re Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data from being recorded in Cloud History must use specific clipboard formats; and Firefox before v
nvd
CVE-2023-5169P4MEDIUMCVSS 6.5fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5169 [MEDIUM] CWE-787 CVE-2023-5169: A compromised content process could have provided malicious data in a `PathRecording` resulting in a A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2023-6865P4MEDIUMCVSS 6.5fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6865 [MEDIUM] CVE-2023-6865: `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be a `EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local disk which may have implications for private browsing mode. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
nvd
CVE-2023-5727P4MEDIUMCVSS 6.5fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5727 [MEDIUM] CVE-2023-5727: The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxb The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-4053P4MEDIUMCVSS 6.5≥ unspecified, < 115.22023-08-01
CVE-2023-4053 [MEDIUM] CWE-59 CVE-2023-4053: A website could have obscured the full screen notification by using a URL with a scheme handled by a A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2022-45410P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45410 [MEDIUM] CWE-862 CVE-2022-45410: When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request w When a ServiceWorker intercepted a request with FetchEvent, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2021-23982P4MEDIUMCVSS 6.5fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23982 [MEDIUM] CWE-326 CVE-2021-23982: Using techniques that built on the slipstream research, a malicious webpage could have scanned both Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.
nvd
CVE-2024-0753P4MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0753 [MEDIUM] CVE-2024-0753: In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerabil In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2022-45408P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45408 [MEDIUM] CWE-79 CVE-2022-45408: Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen wi Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2022-26386P4MEDIUMCVSS 6.5fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26386 [MEDIUM] CWE-377 CVE-2022-26386: Previously Firefox for macOS and Linux would download temporary files to a user-specific directory i Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in /tmp, but this behavior was changed to download them to /tmp where they could be affected by other local users. This behavior was reverted to the original, user-specific directory. *This bug only affects Firefox for macOS and Linux. Other operating
nvd
CVE-2024-1547P4MEDIUMCVSS 6.5≥ unspecified, < 115.82024-02-20
CVE-2024-1547 [MEDIUM] CWE-290 CVE-2024-1547: Through a series of API calls and redirects, an attacker-controlled alert dialog could have been dis Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2023-4574P4MEDIUMCVSS 6.5fixed in 102.15≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4574 [MEDIUM] CWE-416 CVE-2023-4574: When creating a callback over IPC for showing the Color Picker window, multiple of the same callback When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox
nvd
CVE-2023-4575P4MEDIUMCVSS 6.5fixed in 102.15≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4575 [MEDIUM] CWE-416 CVE-2023-4575: When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of the callbacks finished. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox E
nvd
CVE-2023-23598P4MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23598 [MEDIUM] CVE-2023-23598: Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plai Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase