cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 36 of 45
CVE-2022-31738P4MEDIUMCVSS 6.5fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31738 [MEDIUM] CWE-290 CVE-2022-31738: When exiting fullscreen mode, an iframe could have confused the browser about the current state of f When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2023-4580P4MEDIUMCVSS 6.5fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4580 [MEDIUM] CWE-311 CVE-2023-4580: Push notifications stored on disk in private browsing mode were not being encrypted potentially allo Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2023-28164P4MEDIUMCVSS 6.5fixed in 102.9≥ unspecified, < 102.92023-06-02
CVE-2023-28164 [MEDIUM] CWE-346 CVE-2023-28164: Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user co Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.
nvd
CVE-2024-2610P4MEDIUMCVSS 6.1≥ unspecified, < 115.92024-03-19
CVE-2024-2610 [MEDIUM] CWE-94 CVE-2024-2610: Using a markup injection an attacker could have stolen nonce values. This could have been used to by Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2024-9397P4MEDIUMCVSS 6.1fixed in 128.3.0≥ unspecified, < 128.32024-10-01
CVE-2024-9397 [MEDIUM] CWE-1021 CVE-2024-9397: A missing delay in directory upload UI could have made it possible for an attacker to trick a user i A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2024-3859P4MEDIUMCVSS 5.9≥ unspecified, < 115.102024-04-16
CVE-2024-3859 [MEDIUM] CWE-125 CVE-2024-3859: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially c On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2018-18494P4MEDIUMCVSS 6.5≥ unspecified, < 60.42019-02-28
CVE-2018-18494 [MEDIUM] CWE-346 CVE-2018-18494: A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascr A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2019-11736P4HIGHCVSS 7.0fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11736 [HIGH] CWE-362 CVE-2019-11736: The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenanc
nvd
CVE-2020-15652P4MEDIUMCVSS 6.5fixed in 68.11≥ unspecified, < 68.11+1 more2020-08-10
CVE-2020-15652 [MEDIUM] CWE-346 CVE-2020-15652: By observing the stack trace for JavaScript errors in web workers, it was possible to leak the resul By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.
nvd
CVE-2021-29945P4MEDIUMCVSS 6.5fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-29945 [MEDIUM] CWE-682 CVE-2021-29945: The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read an The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2020-26961P4MEDIUMCVSS 6.5fixed in 78.52020-12-09
CVE-2020-26961 [MEDIUM] CVE-2020-26961: When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the respo When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let through, leading to a potential DNS Rebinding attack. This vulnerability affects Firefox < 83, Firefox ESR <
nvd
CVE-2021-38492P4MEDIUMCVSS 6.5fixed in 78.14≥ unspecified, < 78.14+1 more2021-11-03
CVE-2021-38492 [MEDIUM] CVE-2021-38492: When delegating navigations to the operating system, Firefox would accept the `mk` scheme which migh When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92, Thunderbird < 91.1, Thunderbird < 7
nvd
CVE-2018-18499P4MEDIUMCVSS 6.5fixed in 60.2≥ unspecified, < 60.22019-02-28
CVE-2018-18499 [MEDIUM] CWE-346 CVE-2018-18499: A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.
nvd
CVE-2019-11748P4MEDIUMCVSS 6.5fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11748 [MEDIUM] CWE-281 CVE-2019-11748: WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camer WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This avoids the possibility of trusted WebRTC resources being invisibly embe
nvd
CVE-2016-9074P4MEDIUMCVSS 5.9≥ unspecified, < 45.52018-06-11
CVE-2016-9074 [MEDIUM] CWE-200 CVE-2016-9074: An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This is An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2023-6205P4MEDIUMCVSS 6.5fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6205 [MEDIUM] CWE-416 CVE-2023-6205: It was possible to cause the use of a MessagePort after it had already been freed, which could poten It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2022-22742P4MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22742 [MEDIUM] CWE-125 CVE-2022-22742: When inserting text while in edit mode, some characters might have lead to out-of-bounds memory acce When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-29535P4MEDIUMCVSS 6.5fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29535 [MEDIUM] CVE-2023-29535: Following a Garbage Collector compaction, weak maps may have been accessed before they were correctl Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvd
CVE-2024-0746P4MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0746 [MEDIUM] CWE-416 CVE-2024-0746: A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerabi A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2022-45403P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45403 [MEDIUM] CWE-203 CVE-2022-45403: Service Workers should not be able to infer information about opaque cross-origin responses; but tim Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase