cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 37 of 45
CVE-2021-23998P4MEDIUMCVSS 6.5fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-23998 [MEDIUM] CWE-345 CVE-2021-23998: Through complicated navigations with new windows, an HTTP page could have inherited a secure lock ic Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2021-38497P4MEDIUMCVSS 6.5fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38497 [MEDIUM] CWE-346 CVE-2021-38497: Through use of reportValidity() and window.open(), a plain-text validation message could have been o Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvd
CVE-2023-29547P4MEDIUMCVSS 6.5fixed in 102.102023-06-02
CVE-2023-29547 [MEDIUM] CVE-2023-29547: When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
nvd
CVE-2023-23601P4MEDIUMCVSS 6.5fixed in 102.7≥ unspecified, < 102.72023-06-02
CVE-2023-23601 [MEDIUM] CWE-346 CVE-2023-23601: Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab whic Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.
nvd
CVE-2024-2609P4MEDIUMCVSS 6.1≥ unspecified, < 115.102024-03-19
CVE-2024-2609 [MEDIUM] CWE-356 CVE-2024-2609: The permission prompt input delay could expire while the window is not in focus. This makes it vulne The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2024-5693P4MEDIUMCVSS 6.1≥ unspecified, < 115.122024-06-11
CVE-2024-5693 [MEDIUM] CWE-829 CVE-2024-5693: Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image d Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2023-4049P4MEDIUMCVSS 5.9≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4049 [MEDIUM] CWE-362 CVE-2023-4049: Race conditions in reference counting code were found through code inspection. These could have resu Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2020-12413P4MEDIUMCVSS 5.9fixed in 68.10.0≥ unspecified, < 68.102023-02-16
CVE-2020-12413 [MEDIUM] CWE-203 CVE-2020-12413: The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitig The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
nvd
CVE-2022-22746P4MEDIUMCVSS 5.9fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22746 [MEDIUM] CWE-362 CVE-2022-22746: A race condition could have allowed bypassing the fullscreen notification which could have lead to a A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2017-7791P4MEDIUMCVSS 5.3≥ unspecified, < 52.32018-06-11
CVE-2017-7791 [MEDIUM] CWE-20 CVE-2017-7791: On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will re On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2021-29955P4MEDIUMCVSS 5.3fixed in 78.9≥ unspecified, < 78.92021-06-24
CVE-2021-29955 [MEDIUM] CWE-74 CVE-2021-29955: A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and may have also enabled JIT type confusion attacks. (A related vulnerability, Speculative Code Store Bypass (SCSB), did not affect Firefox.). This vulnerability affects Firefox ESR < 78.9 and Firefox < 87.
nvd
CVE-2019-11698P4MEDIUMCVSS 5.3≥ unspecified, < 60.72019-07-23
CVE-2019-11698 [MEDIUM] CWE-20 CVE-2019-11698: If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookm If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This
nvd
CVE-2026-15719P4MEDIUMCVSS 5.4fixed in Firefox ESR 140.13
CVE-2026-15719 [MEDIUM] Mozilla Foundation Security Advisory 2026-70: CVE-2026-15719 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-15719 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2021-29964P4HIGHCVSS 7.1fixed in 78.11≥ unspecified, < 78.112021-06-24
CVE-2021-29964 [HIGH] CWE-125 CVE-2021-29964: A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process inc A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 78.11, Firefox < 89, and Firefox ESR < 78.11.
nvd
CVE-2026-6762P4UNKNOWNfixed in Firefox ESR 115.35
CVE-2026-6762 Mozilla Foundation Security Advisory 2026-31: CVE-2026-6762 Mozilla Foundation Security Advisory 2026-31 CVE: CVE-2026-6762 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.35
mozilla
CVE-2012-0460P4MEDIUMCVSS 6.4v10.1v10.22012-03-14
CVE-2012-0460 [MEDIUM] CWE-264 CVE-2012-0460: Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thun Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to the window.fullScreen object, which allows remote attackers to spoof the user interface via a crafted web page.
nvd
CVE-2021-43545P4MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43545 [MEDIUM] CWE-834 CVE-2021-43545: Using the Location API in a loop could have caused severe application hangs and crashes. This vulner Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2019-11750P4MEDIUMCVSS 6.5fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11750 [MEDIUM] CWE-843 CVE-2019-11750: A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. Thi A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
nvd
CVE-2019-17016P4MEDIUMCVSS 6.1fixed in 68.4vbefore 68.42020-01-08
CVE-2019-17016 [MEDIUM] CWE-79 CVE-2019-17016: When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incor When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites resulting in data exfiltration. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2022-40960P4MEDIUMCVSS 6.5fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40960 [MEDIUM] CWE-416 CVE-2022-40960: Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-a Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase