cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 35 of 45
CVE-2019-11747P4MEDIUMCVSS 6.5fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11747 [MEDIUM] CWE-665 CVE-2019-11747: The "Forget about this site" feature in the History pane is intended to remove all saved user data t The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Due to a bug, sites on the pre-load list also have their HSTS setting removed. On the next visit to tha
nvd
CVE-2021-23984P4MEDIUMCVSS 6.5fixed in 78.9≥ unspecified, < 78.92021-03-31
CVE-2021-23984 [MEDIUM] CWE-290 CVE-2021-23984: A malicious extension could have opened a popup window lacking an address bar. The title of the popu A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, a
nvd
CVE-2022-40958P4MEDIUMCVSS 6.5fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40958 [MEDIUM] CWE-74 CVE-2022-40958: By injecting a cookie with certain special characters, an attacker on a shared subdomain which is no By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2022-40957P4MEDIUMCVSS 6.5fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40957 [MEDIUM] CWE-240 CVE-2022-40957: Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2023-5171P4MEDIUMCVSS 6.5fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5171 [MEDIUM] CWE-416 CVE-2023-5171: During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allo During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2019-11738P4MEDIUMCVSS 6.3fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11738 [MEDIUM] CVE-2019-11738: If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of any javascript: URIs will be allowed. This could allow for malicious JavaScript content to be run, bypassing CSP permissions. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
nvd
CVE-2018-5131P4MEDIUMCVSS 5.9≥ unspecified, < 52.72018-06-11
CVE-2018-5131 [MEDIUM] CWE-200 CVE-2018-5131: Under certain circumstances the "fetch()" API can return transient local copies of resources that we Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored, locally cached data of a website being accessible to users if they share a common profile while brows
nvd
CVE-2023-28163P4MEDIUMCVSS 6.5fixed in 102.9≥ unspecified, < 102.102023-06-02
CVE-2023-28163 [MEDIUM] CWE-22 CVE-2023-28163: When downloading files through the Save As dialog on Windows with suggested filenames containing env When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those in the context of the current user. *This bug only affects Firefox on Windows. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thu
nvd
CVE-2023-32211P4MEDIUMCVSS 6.5fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32211 [MEDIUM] CVE-2023-32211: A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefo A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2022-22748P4MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22748 [MEDIUM] CWE-79 CVE-2022-22748: Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2022-29916P4MEDIUMCVSS 6.5fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29916 [MEDIUM] CWE-200 CVE-2022-29916: Firefox behaved slightly differently for already known resources when loading CSS resources involvin Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2022-1196P4MEDIUMCVSS 6.5fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-1196 [MEDIUM] CWE-416 CVE-2022-1196: After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8 and Firefox ESR < 91.8.
nvd
CVE-2023-25751P4MEDIUMCVSS 6.5fixed in 102.9≥ unspecified, < 102.92023-06-02
CVE-2023-25751 [MEDIUM] CVE-2023-25751: Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd
CVE-2022-45416P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45416 [MEDIUM] CWE-203 CVE-2022-45416: Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have possibly figured out which keys were being pressed. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2022-46880P4MEDIUMCVSS 6.5fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46880 [MEDIUM] CWE-416 CVE-2022-46880: A missing check related to tex units could have led to a use-after-free and potentially exploitable A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 105. This vulnerability affects Firefox ESR < 102.6, Firefox < 105, and Thunderbird
nvd
CVE-2022-22745P4MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22745 [MEDIUM] CWE-200 CVE-2022-22745: Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violat Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-1945P4MEDIUMCVSS 6.5fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-1945 [MEDIUM] CWE-787 CVE-2023-1945: Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potent Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 102.10 and Firefox ESR < 102.10.
nvd
CVE-2023-25738P4MEDIUMCVSS 6.5fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25738 [MEDIUM] CWE-125 CVE-2023-25738: Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thu
nvd
CVE-2022-29914P4MEDIUMCVSS 6.5fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29914 [MEDIUM] CWE-1021 CVE-2022-29914: When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI When reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofing attacks. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2022-31742P4MEDIUMCVSS 6.5fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31742 [MEDIUM] CWE-203 CVE-2022-31742: An attacker could have exploited a timing attack by sending a large number of allowCredential entrie An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR
nvd
Mozilla Firefox Esr vulnerabilities | cvebase