cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 40 of 45
CVE-2026-12298P4MEDIUMCVSS 5.4fixed in Firefox ESR 140.12
CVE-2026-12298 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12298 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12298 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-8391P4MEDIUMCVSS 5.3fixed in Firefox ESR 115.36
CVE-2026-8391 [MEDIUM] Mozilla Foundation Security Advisory 2026-47: CVE-2026-8391 Mozilla Foundation Security Advisory 2026-47 CVE: CVE-2026-8391 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.36
mozilla
CVE-2014-8638P4MEDIUMCVSS 6.8v31.22015-01-14
CVE-2014-8638 [MEDIUM] CWE-352 CVE-2014-8638: The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4 The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.
nvd
CVE-2019-17022P4MEDIUMCVSS 6.1fixed in 68.4vbefore 68.42020-01-08
CVE-2019-17022 [MEDIUM] CWE-79 CVE-2019-17022: When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer does not escape characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, th
nvd
CVE-2022-40956P4MEDIUMCVSS 6.1fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40956 [MEDIUM] CWE-79 CVE-2022-40956: When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and acce When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2022-45418P4MEDIUMCVSS 6.1fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45418 [MEDIUM] CWE-1021 CVE-2022-45418: If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2022-29912P4MEDIUMCVSS 6.1fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29912 [MEDIUM] CWE-601 CVE-2022-29912: Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2017-5408P4MEDIUMCVSS 5.3≥ unspecified, < 45.82018-06-11
CVE-2017-5408 [MEDIUM] CWE-200 CVE-2017-5408: Video files loaded video captions cross-origin without checking for the presence of CORS headers per Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5405P4MEDIUMCVSS 5.3≥ unspecified, < 45.82018-06-11
CVE-2017-5405 [MEDIUM] CWE-1187 CVE-2017-5405: Certain response codes in FTP connections can result in the use of uninitialized values for ports in Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2019-11762P4MEDIUMCVSS 6.1fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11762 [MEDIUM] CWE-346 CVE-2019-11762: If two same-origin documents set document.domain differently to become cross-origin, it was possible If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2018-5117P4MEDIUMCVSS 5.3≥ unspecified, < 52.62018-06-11
CVE-2018-5117 [MEDIUM] CVE-2018-5117: If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird <
nvd
CVE-2018-5168P4MEDIUMCVSS 5.3≥ unspecified, < 52.82018-06-11
CVE-2018-5168 [MEDIUM] CVE-2018-5168: Sites can bypass security checks on permissions to install lightweight themes by manipulating the "b Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and F
nvd
CVE-2024-8386P4MEDIUMCVSS 6.1fixed in 128.2≥ unspecified, < 128.22024-09-03
CVE-2024-8386 [MEDIUM] CWE-601 CVE-2024-8386: If a site had been granted the permission to open popup windows, it could cause Select elements to a If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvd
CVE-2019-11717P4MEDIUMCVSS 5.3≥ unspecified, < 60.82019-07-23
CVE-2019-11717 [MEDIUM] CWE-116 CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2017-7764P4MEDIUMCVSS 5.3≥ unspecified, < 52.22018-06-11
CVE-2017-7764 [MEDIUM] CWE-20 CVE-2017-7764: Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unico Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syl
nvd
CVE-2019-17021P4MEDIUMCVSS 5.3fixed in 68.4vbefore 68.42020-01-08
CVE-2019-17021 [MEDIUM] CWE-362 CVE-2019-17021: During the initialization of a new content process, a race condition occurs that can allow a content During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2018-12381P4MEDIUMCVSS 5.3≥ unspecified, < 60.22018-10-18
CVE-2018-12381 [MEDIUM] CWE-610 CVE-2018-12381: Manually dragging and dropping an Outlook email message into the browser will trigger a page navigat Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Fi
nvd
CVE-2017-7763P4MEDIUMCVSS 5.3≥ unspecified, < 52.22018-06-11
CVE-2017-7763 [MEDIUM] CWE-20 CVE-2017-7763: Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2023-6206P4MEDIUMCVSS 5.4fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6206 [MEDIUM] CWE-1021 CVE-2023-6206: The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking dela The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2024-11695P4MEDIUMCVSS 5.4≥ unspecified, < 128.52024-11-26
CVE-2024-11695 [MEDIUM] CWE-1021 CVE-2024-11695: A crafted URL containing Arabic script and whitespace characters could have hidden the true origin o A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase