cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 35 of 49
CVE-2022-45405P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45405 [MEDIUM] CWE-416 CVE-2022-45405: Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led t Freeing arbitrary nsIInputStream's on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2022-46875P4MEDIUMCVSS 6.5fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46875 [MEDIUM] CWE-287 CVE-2022-46875: The executable file warning was not presented when downloading .atloc and .ftploc files, which can r The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvd
CVE-2024-5692P4MEDIUMCVSS 6.5≥ unspecified, < 115.122024-06-11
CVE-2024-5692 [MEDIUM] CVE-2024-5692: On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser in On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firef
nvd
CVE-2023-25752P4MEDIUMCVSS 6.5fixed in 102.9≥ unspecified, < 102.92023-06-02
CVE-2023-25752 [MEDIUM] CVE-2023-25752: When accessing throttled streams, the count of available bytes needed to be checked in the calling f When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd
CVE-2022-31744P4MEDIUMCVSS 6.5fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-31744 [MEDIUM] CWE-79 CVE-2022-31744: An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource: An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101.
nvd
CVE-2022-45420P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45420 [MEDIUM] CWE-1021 CVE-2022-45420: Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2024-10462P4MEDIUMCVSS 6.5≥ unspecified, < 128.42024-10-29
CVE-2024-10462 [MEDIUM] CWE-290 CVE-2024-10462: Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerabili Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2024-10465P4MEDIUMCVSS 6.5≥ unspecified, < 128.42024-10-29
CVE-2024-10465 [MEDIUM] CWE-290 CVE-2024-10465: A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerabi A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2024-7529P4MEDIUMCVSS 6.5fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7529 [MEDIUM] CWE-451 CVE-2024-7529: The date picker could partially obscure security prompts. This could be used by a malicious site to The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2026-8388P4MEDIUMCVSS 6.5fixed in Firefox ESR 115.36
CVE-2026-8388 [MEDIUM] Mozilla Foundation Security Advisory 2026-47: CVE-2026-8388 Mozilla Foundation Security Advisory 2026-47 CVE: CVE-2026-8388 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.36
mozilla
CVE-2019-9793P4MEDIUMCVSS 5.9fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9793 [MEDIUM] CWE-119 CVE-2019-9793: A mechanism was discovered that removes some bounds checking for string, array, or typed array acces A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for which the range analysis will infer a fully controlled, incorrect range in circumstances where users have
nvd
CVE-2024-6600P4MEDIUMCVSS 6.3≥ unspecified, < 115.132024-07-09
CVE-2024-6600 [MEDIUM] CWE-770 CVE-2024-6600: Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access c Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2011-3079P4CRITICALCVSS 10.0≥ unspecified, < 60.52012-05-01
CVE-2011-3079 [CRITICAL] CWE-399 CVE-2011-3079: The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.
nvd
CVE-2017-5407P4MEDIUMCVSS 6.5≥ unspecified, < 45.82018-06-11
CVE-2017-5407 [MEDIUM] CWE-200 CVE-2017-5407: Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Fire
nvd
CVE-2018-12396P4MEDIUMCVSS 6.5fixed in 60.3≥ unspecified, < 60.32019-02-28
CVE-2018-12396 [MEDIUM] CWE-732 CVE-2018-12396: A vulnerability where a WebExtension can run content scripts in disallowed contexts following naviga A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
nvd
CVE-2022-28282P4MEDIUMCVSS 6.5fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28282 [MEDIUM] CWE-416 CVE-2022-28282: By using a link with <code>rel="localization"</code> a use-after-free could have been triggered by d By using a link with rel="localization" a use-after-free could have been triggered by destroying an object during JavaScript execution and then referencing the object through a freed pointer, leading to a potential exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvd
CVE-2026-74984P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74984 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74984 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74984 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2018-12397P4HIGHCVSS 7.1≥ unspecified, < 60.32019-02-28
CVE-2018-12397 [HIGH] CWE-200 CVE-2018-12397: A WebExtension can request access to local files without the warning prompt stating that the extensi A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63
nvd
CVE-2020-12421P4MEDIUMCVSS 6.5fixed in 68.10.0≥ unspecified, < 68.102020-07-09
CVE-2020-12421 [MEDIUM] CWE-295 CVE-2020-12421: When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected ( When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become out-of-date silently without notification to the user. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10.0.
nvd
CVE-2021-43542P4MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43542 [MEDIUM] CWE-209 CVE-2021-43542: Using XMLHttpRequest, an attacker could have identified installed applications by probing error mess Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase