cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 4 of 49
CVE-2026-84121P3CRITICALCVSS 9.6fixed in Firefox ESR 140.15
CVE-2026-84121 [CRITICAL] Mozilla Foundation Security Advisory 2026-84: CVE-2026-84121 Mozilla Foundation Security Advisory 2026-84 CVE: CVE-2026-84121 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.15
mozilla
CVE-2026-74985P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74985 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74985 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74985 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74979P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74979 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74979 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74979 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-16349P3UNKNOWNfixed in Firefox ESR 115.38
CVE-2026-16349 Mozilla Foundation Security Advisory 2026-69: CVE-2026-16349 Mozilla Foundation Security Advisory 2026-69 CVE: CVE-2026-16349 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.38
mozilla
CVE-2026-84133P3UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84133 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84133 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84133 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2026-84129P3UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84129 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84129 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84129 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2026-84140P3UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84140 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84140 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84140 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2022-22744P3HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22744 [HIGH] CWE-116 CVE-2022-22744: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped fo The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunder
nvd
CVE-2017-5461P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12017-05-11
CVE-2017-5461 [CRITICAL] CWE-787 CVE-2017-5461: Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x b Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
nvd
CVE-2024-11697P3HIGHCVSS 8.8≥ unspecified, < 128.52024-11-26
CVE-2024-11697 [HIGH] CWE-94 CVE-2024-11697: When handling keypress events, an attacker may have been able to trick a user into bypassing the "Op When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2017-5456P3CRITICALCVSS 9.8≥ unspecified, < 52.12018-06-11
CVE-2017-5456 [CRITICAL] CWE-732 CVE-2017-5456: A mechanism to bypass file system access protections in the sandbox using the file system request co A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
nvd
CVE-2026-12328P3HIGHCVSS 8.1fixed in Firefox ESR 115.37
CVE-2026-12328 [HIGH] Mozilla Foundation Security Advisory 2026-59: CVE-2026-12328 Mozilla Foundation Security Advisory 2026-59 CVE: CVE-2026-12328 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.37
mozilla
CVE-2015-2733P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2733 [CRITICAL] CVE-2015-2733: Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.
nvd
CVE-2015-2722P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2722 [CRITICAL] CVE-2015-2722: Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.
nvd
CVE-2018-18500P3CRITICALCVSS 9.8fixed in 60.52019-02-05
CVE-2018-18500 [CRITICAL] CWE-416 CVE-2018-18500: A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML e A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
nvd
CVE-2014-1544P3CRITICALCVSS 10.0v24.2v24.3+3 more2014-07-23
CVE-2014-1544 [CRITICAL] CVE-2014-1544: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Networ Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a
nvd
CVE-2026-8974P3CRITICALCVSS 9.8fixed in Firefox ESR 140.11
CVE-2026-8974 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8974 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8974 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-74943P3UNKNOWNfixed in Firefox ESR 115.39
CVE-2026-74943 Mozilla Foundation Security Advisory 2026-75: CVE-2026-74943 Mozilla Foundation Security Advisory 2026-75 CVE: CVE-2026-74943 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.39
mozilla
CVE-2026-16350P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16350 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16350 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16350 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16351P3UNKNOWNfixed in Firefox ESR 115.38
CVE-2026-16351 Mozilla Foundation Security Advisory 2026-69: CVE-2026-16351 Mozilla Foundation Security Advisory 2026-69 CVE: CVE-2026-16351 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.38
mozilla
Mozilla Firefox Esr vulnerabilities | cvebase