cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 39 of 45
CVE-2020-15677P4MEDIUMCVSS 6.1fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15677 [MEDIUM] CWE-601 CVE-2020-15677: By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site d By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2023-4578P4MEDIUMCVSS 6.5fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4578 [MEDIUM] CWE-770 CVE-2023-4578: When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling ` When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a newly created Out of Memory exception to be mishandled as a Syntax Error. This vulnerability affects Firefox < 117,
nvd
CVE-2020-15676P4MEDIUMCVSS 6.1fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15676 [MEDIUM] CWE-79 CVE-2020-15676: Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2020-26951P4MEDIUMCVSS 6.1fixed in 78.52020-12-09
CVE-2020-26951 [MEDIUM] CWE-79 CVE-2020-26951: A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, e A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbi
nvd
CVE-2017-5462P4MEDIUMCVSS 5.3≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5462 [MEDIUM] CWE-682 CVE-2017-5462: A flaw in DRBG number generation within the Network Security Services (NSS) library where the intern A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Fir
nvd
CVE-2022-45411P4MEDIUMCVSS 6.1fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45411 [MEDIUM] CWE-79 CVE-2022-45411: Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an X Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on fetch() and XMLHttpRequest; however some webservers have implemented non-sta
nvd
CVE-2024-10461P4MEDIUMCVSS 6.1≥ unspecified, < 128.42024-10-29
CVE-2024-10461 [MEDIUM] CWE-79 CVE-2024-10461: In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2022-29911P4MEDIUMCVSS 6.1fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29911 [MEDIUM] CWE-1021 CVE-2022-29911: An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-acti An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation could lead to script execution without allow-scripts being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2024-4768P4MEDIUMCVSS 6.1≥ unspecified, < 115.112024-05-14
CVE-2024-4768 [MEDIUM] CWE-281 CVE-2024-4768: A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a us A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2024-1549P4MEDIUMCVSS 6.1≥ unspecified, < 115.82024-02-20
CVE-2024-1549 [MEDIUM] CVE-2024-1549: If a website set a large custom cursor, portions of the cursor could have overlapped with the permis If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2016-9064P4MEDIUMCVSS 5.9≥ unspecified, < 45.52018-06-11
CVE-2016-9064 [MEDIUM] CWE-295 CVE-2016-9064: Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the a Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinning protection could provide a malicious signed add-on instead of a valid update. This vulnerabili
nvd
CVE-2024-11694P4MEDIUMCVSS 6.1≥ unspecified, < 128.5≥ unspecified, < 115.182024-11-26
CVE-2024-11694 [MEDIUM] CWE-79 CVE-2024-11694: Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass a Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ES
nvd
CVE-2024-7524P4MEDIUMCVSS 6.1fixed in 115.14≥ 116.0, < 128.1+2 more2024-08-06
CVE-2024-7524 [MEDIUM] CWE-79 CVE-2024-7524: Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. Thi
nvd
CVE-2024-4769P4MEDIUMCVSS 5.9≥ unspecified, < 115.112024-05-14
CVE-2024-4769 [MEDIUM] CWE-351 CVE-2024-4769: When importing resources using Web Workers, error messages would distinguish the difference between When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2017-7825P4MEDIUMCVSS 5.3≥ unspecified, < 52.42018-06-11
CVE-2017-7825 [MEDIUM] CWE-20 CVE-2017-7825: Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the add Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.
nvd
CVE-2020-6812P4MEDIUMCVSS 5.3fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6812 [MEDIUM] CWE-200 CVE-2020-6812: The first time AirPods are connected to an iPhone, they become named after the user's name by defaul The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to sim
nvd
CVE-2024-2611P4MEDIUMCVSS 5.5≥ unspecified, < 115.92024-03-19
CVE-2024-2611 [MEDIUM] CVE-2024-2611: A missing delay on when pointer lock was used could have allowed a malicious page to trick a user in A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2019-11761P4MEDIUMCVSS 5.4fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11761 [MEDIUM] CWE-362 CVE-2019-11761: By using a form with a data URI it was possible to gain access to the privileged JSONView object tha By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2024-11696P4MEDIUMCVSS 5.4≥ unspecified, < 128.52024-11-26
CVE-2024-11696 [MEDIUM] CWE-347 CVE-2024-11696: The application failed to account for exceptions thrown by the `loadManifestFromFile` method during The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated ad
nvd
CVE-2023-4045P4MEDIUMCVSS 5.3≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4045 [MEDIUM] CWE-346 CVE-2023-4045: Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase