Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 39 of 49
CVE-2022-31742P4MEDIUMCVSS 6.5fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31742 [MEDIUM] CWE-203 CVE-2022-31742: An attacker could have exploited a timing attack by sending a large number of allowCredential entrie
An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR
nvd
CVE-2022-31738P4MEDIUMCVSS 6.5fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31738 [MEDIUM] CWE-290 CVE-2022-31738: When exiting fullscreen mode, an iframe could have confused the browser about the current state of f
When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2023-4580P4MEDIUMCVSS 6.5fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4580 [MEDIUM] CWE-311 CVE-2023-4580: Push notifications stored on disk in private browsing mode were not being encrypted potentially allo
Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2024-2610P4MEDIUMCVSS 6.1≥ unspecified, < 115.92024-03-19
CVE-2024-2610 [MEDIUM] CWE-94 CVE-2024-2610: Using a markup injection an attacker could have stolen nonce values. This could have been used to by
Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2024-9397P4MEDIUMCVSS 6.1fixed in 128.3.0≥ unspecified, < 128.32024-10-01
CVE-2024-9397 [MEDIUM] CWE-1021 CVE-2024-9397: A missing delay in directory upload UI could have made it possible for an attacker to trick a user i
A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2024-3859P4MEDIUMCVSS 5.9≥ unspecified, < 115.102024-04-16
CVE-2024-3859 [MEDIUM] CWE-125 CVE-2024-3859: On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially c
On 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenType font. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2021-43545P4MEDIUMCVSS 6.5fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43545 [MEDIUM] CWE-834 CVE-2021-43545: Using the Location API in a loop could have caused severe application hangs and crashes. This vulner
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2018-18494P4MEDIUMCVSS 6.5≥ unspecified, < 60.42019-02-28
CVE-2018-18494 [MEDIUM] CWE-346 CVE-2018-18494: A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascr
A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2019-11736P4HIGHCVSS 7.0fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11736 [HIGH] CWE-362 CVE-2019-11736: The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the
The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenanc
nvd
CVE-2021-29945P4MEDIUMCVSS 6.5fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-29945 [MEDIUM] CWE-682 CVE-2021-29945: The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read an
The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2020-15658P4MEDIUMCVSS 6.5fixed in 78.1≥ unspecified, < 78.12020-08-10
CVE-2020-15658 [MEDIUM] CWE-754 CVE-2020-15658: The code for downloading files did not properly take care of special characters, which led to an att
The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file type being downloaded than shown in the dialog. This vulnerability affects Firefox ESR < 78.1, Firefox < 79, and Thunderbird < 78.1.
nvd
CVE-2019-11748P4MEDIUMCVSS 6.5fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11748 [MEDIUM] CWE-281 CVE-2019-11748: WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camer
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context. In light of recent high profile vulnerabilities in other software, a decision was made to no longer persist these permissions. This avoids the possibility of trusted WebRTC resources being invisibly embe
nvd
CVE-2016-9074P4MEDIUMCVSS 5.9≥ unspecified, < 45.52018-06-11
CVE-2016-9074 [MEDIUM] CWE-200 CVE-2016-9074: An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This is
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2023-6205P4MEDIUMCVSS 6.5fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6205 [MEDIUM] CWE-416 CVE-2023-6205: It was possible to cause the use of a MessagePort after it had already been freed, which could poten
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2022-22742P4MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22742 [MEDIUM] CWE-125 CVE-2022-22742: When inserting text while in edit mode, some characters might have lead to out-of-bounds memory acce
When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-29535P4MEDIUMCVSS 6.5fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29535 [MEDIUM] CVE-2023-29535: Following a Garbage Collector compaction, weak maps may have been accessed before they were correctl
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
nvd
CVE-2024-0746P4MEDIUMCVSS 6.5fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0746 [MEDIUM] CWE-416 CVE-2024-0746: A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerabi
A Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2022-45403P4MEDIUMCVSS 6.5fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45403 [MEDIUM] CWE-203 CVE-2022-45403: Service Workers should not be able to infer information about opaque cross-origin responses; but tim
Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2021-23998P4MEDIUMCVSS 6.5fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-23998 [MEDIUM] CWE-345 CVE-2021-23998: Through complicated navigations with new windows, an HTTP page could have inherited a secure lock ic
Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2021-38497P4MEDIUMCVSS 6.5fixed in 91.2≥ unspecified, < 91.22021-11-03
CVE-2021-38497 [MEDIUM] CWE-346 CVE-2021-38497: Through use of reportValidity() and window.open(), a plain-text validation message could have been o
Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox < 93, Thunderbird < 91.2, and Firefox ESR < 91.2.
nvd