cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 38 of 45
CVE-2022-22760P4MEDIUMCVSS 6.5fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22760 [MEDIUM] CWE-209 CVE-2022-22760: When importing resources using Web Workers, error messages would distinguish the difference between When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2023-32206P4MEDIUMCVSS 6.5fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32206 [MEDIUM] CWE-125 CVE-2023-32206: An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2023-25742P4MEDIUMCVSS 6.5fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25742 [MEDIUM] CVE-2023-25742: When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing th When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2022-22747P4MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22747 [MEDIUM] CWE-295 CVE-2022-22747: After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificat After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2020-26958P4MEDIUMCVSS 6.1fixed in 78.52020-12-09
CVE-2020-26958 [MEDIUM] CWE-79 CVE-2020-26958: Firefox did not block execution of scripts with incorrect MIME types when the response was intercept Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2020-26978P4MEDIUMCVSS 6.1fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-26978 [MEDIUM] CVE-2020-26978: Using techniques that built on the slipstream research, a malicious webpage could have exposed both Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2024-1551P4MEDIUMCVSS 6.1≥ unspecified, < 115.82024-02-20
CVE-2024-1551 [MEDIUM] CWE-565 CVE-2024-1551: Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attack Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, an
nvd
CVE-2023-6867P4MEDIUMCVSS 6.1fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6867 [MEDIUM] CWE-1021 CVE-2023-6867: The timing of a button click causing a popup to disappear was approximately the same length as the a The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
nvd
CVE-2024-1550P4MEDIUMCVSS 6.1≥ unspecified, < 115.82024-02-20
CVE-2024-1550 [MEDIUM] CWE-1021 CVE-2024-1550: A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 1
nvd
CVE-2024-10460P4MEDIUMCVSS 5.3≥ unspecified, < 128.42024-10-29
CVE-2024-10460 [MEDIUM] CWE-346 CVE-2024-10460: The origin of an external protocol handler prompt could have been obscured using a data: URL within The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-12329P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.12
CVE-2026-12329 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12329 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12329 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12308P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.12
CVE-2026-12308 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12308 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12308 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12306P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.12
CVE-2026-12306 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12306 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12306 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12307P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.12
CVE-2026-12307 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12307 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12307 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-6767P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.10
CVE-2026-6767 [MEDIUM] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6767 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6767 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-6765P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.10
CVE-2026-6765 [MEDIUM] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6765 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6765 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2015-0807P4MEDIUMCVSS 6.8v31.1v31.2+3 more2015-04-01
CVE-2015-0807 [MEDIUM] CVE-2015-0807: The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6 The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted w
nvd
CVE-2021-23973P4MEDIUMCVSS 6.5fixed in 78.82021-02-26
CVE-2021-23973 [MEDIUM] CWE-209 CVE-2021-23973: When trying to load a cross-origin resource in an audio/video context a decoding error may have resu When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2020-6798P4MEDIUMCVSS 6.1fixed in 68.5.02020-03-02
CVE-2020-6798 [MEDIUM] CWE-79 CVE-2020-6798: If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsin If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because
nvd
CVE-2022-42929P4MEDIUMCVSS 6.5fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42929 [MEDIUM] CWE-400 CVE-2022-42929: If a website called `window.print()` in a particular way, it could cause a denial of service of the If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase