cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 4 of 45
CVE-2026-6748P3CRITICALCVSS 9.8fixed in Firefox ESR 140.10
CVE-2026-6748 [CRITICAL] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6748 Mozilla Foundation Security Advisory 2026-32 CVE: CVE-2026-6748 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-8401P3CRITICALCVSS 9.8fixed in Firefox ESR 140.11
CVE-2026-8401 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8401 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8401 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-8953P3CRITICALCVSS 9.6fixed in Firefox ESR 115.36
CVE-2026-8953 [CRITICAL] Mozilla Foundation Security Advisory 2026-47: CVE-2026-8953 Mozilla Foundation Security Advisory 2026-47 CVE: CVE-2026-8953 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.36
mozilla
CVE-2026-16363P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16363 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16363 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16363 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16355P3UNKNOWNfixed in Firefox ESR 115.38
CVE-2026-16355 Mozilla Foundation Security Advisory 2026-69: CVE-2026-16355 Mozilla Foundation Security Advisory 2026-69 CVE: CVE-2026-16355 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.38
mozilla
CVE-2026-16350P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16350 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16350 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16350 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16357P3UNKNOWNfixed in Firefox ESR 115.38
CVE-2026-16357 Mozilla Foundation Security Advisory 2026-69: CVE-2026-16357 Mozilla Foundation Security Advisory 2026-69 CVE: CVE-2026-16357 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.38
mozilla
CVE-2026-16368P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16368 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16368 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16368 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16390P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16390 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16390 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16390 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16387P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16387 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16387 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16387 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2022-22744P3HIGHCVSS 8.8fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22744 [HIGH] CWE-116 CVE-2022-22744: The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped fo The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunder
nvd
CVE-2017-5461P3CRITICALCVSS 9.8≥ unspecified, < 45.9≥ unspecified, < 52.12017-05-11
CVE-2017-5461 [CRITICAL] CWE-787 CVE-2017-5461: Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x b Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
nvd
CVE-2024-2614P3HIGHCVSS 8.8≥ unspecified, < 115.92024-03-19
CVE-2024-2614 [HIGH] CWE-787 CVE-2024-2614: Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these b Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2024-11697P3HIGHCVSS 8.8≥ unspecified, < 128.52024-11-26
CVE-2024-11697 [HIGH] CWE-94 CVE-2024-11697: When handling keypress events, an attacker may have been able to trick a user into bypassing the "Op When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2018-18498P3CRITICALCVSS 9.8fixed in 60.4≥ unspecified, < 60.42019-02-28
CVE-2018-18498 [CRITICAL] CWE-190 CVE-2018-18498: A potential vulnerability leading to an integer overflow can occur during buffer size calculations f A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2017-5456P3CRITICALCVSS 9.8≥ unspecified, < 52.12018-06-11
CVE-2017-5456 [CRITICAL] CWE-732 CVE-2017-5456: A mechanism to bypass file system access protections in the sandbox using the file system request co A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
nvd
CVE-2026-12328P3HIGHCVSS 8.1fixed in Firefox ESR 115.37
CVE-2026-12328 [HIGH] Mozilla Foundation Security Advisory 2026-59: CVE-2026-12328 Mozilla Foundation Security Advisory 2026-59 CVE: CVE-2026-12328 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.37
mozilla
CVE-2015-2733P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2733 [CRITICAL] CVE-2015-2733: Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.
nvd
CVE-2015-2722P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2722 [CRITICAL] CVE-2015-2722: Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.
nvd
CVE-2014-1544P3CRITICALCVSS 10.0v24.2v24.3+3 more2014-07-23
CVE-2014-1544 [CRITICAL] CVE-2014-1544: Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Networ Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger certain improper removal of an NSSCertificate structure from a
nvd
Mozilla Firefox Esr vulnerabilities | cvebase