Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 41 of 49
CVE-2022-22760P4MEDIUMCVSS 6.5fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22760 [MEDIUM] CWE-209 CVE-2022-22760: When importing resources using Web Workers, error messages would distinguish the difference between
When importing resources using Web Workers, error messages would distinguish the difference between application/javascript responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2023-32206P4MEDIUMCVSS 6.5fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32206 [MEDIUM] CWE-125 CVE-2023-32206: An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects
An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2023-25742P4MEDIUMCVSS 6.5fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25742 [MEDIUM] CVE-2023-25742: When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing th
When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2022-22747P4MEDIUMCVSS 6.5fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22747 [MEDIUM] CWE-295 CVE-2022-22747: After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificat
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2020-26978P4MEDIUMCVSS 6.1fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-26978 [MEDIUM] CVE-2020-26978: Using techniques that built on the slipstream research, a malicious webpage could have exposed both
Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2024-1551P4MEDIUMCVSS 6.1≥ unspecified, < 115.82024-02-20
CVE-2024-1551 [MEDIUM] CWE-565 CVE-2024-1551: Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attack
Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, an
nvd
CVE-2023-6867P4MEDIUMCVSS 6.1fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6867 [MEDIUM] CWE-1021 CVE-2023-6867: The timing of a button click causing a popup to disappear was approximately the same length as the a
The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox ESR < 115.6 and Firefox < 121.
nvd
CVE-2024-2609P4MEDIUMCVSS 6.1≥ unspecified, < 115.102024-03-19
CVE-2024-2609 [MEDIUM] CWE-356 CVE-2024-2609: The permission prompt input delay could expire while the window is not in focus. This makes it vulne
The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2024-1550P4MEDIUMCVSS 6.1≥ unspecified, < 115.82024-02-20
CVE-2024-1550 [MEDIUM] CWE-1021 CVE-2024-1550: A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock
A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 1
nvd
CVE-2024-4769P4MEDIUMCVSS 5.9≥ unspecified, < 115.112024-05-14
CVE-2024-4769 [MEDIUM] CWE-351 CVE-2024-4769: When importing resources using Web Workers, error messages would distinguish the difference between
When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2020-6812P4MEDIUMCVSS 5.3fixed in 68.6.0≥ unspecified, < 68.62020-03-25
CVE-2020-6812 [MEDIUM] CWE-200 CVE-2020-6812: The first time AirPods are connected to an iPhone, they become named after the user's name by defaul
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to sim
nvd
CVE-2026-84118P4MEDIUMCVSS 5.4fixed in Firefox ESR 153.2
CVE-2026-84118 [MEDIUM] Mozilla Foundation Security Advisory 2026-85: CVE-2026-84118
Mozilla Foundation Security Advisory 2026-85
CVE: CVE-2026-84118
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.2
mozilla
CVE-2026-84125P4MEDIUMCVSS 5.4fixed in Firefox ESR 153.2
CVE-2026-84125 [MEDIUM] Mozilla Foundation Security Advisory 2026-85: CVE-2026-84125
Mozilla Foundation Security Advisory 2026-85
CVE: CVE-2026-84125
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.2
mozilla
CVE-2024-10460P4MEDIUMCVSS 5.3≥ unspecified, < 128.42024-10-29
CVE-2024-10460 [MEDIUM] CWE-346 CVE-2024-10460: The origin of an external protocol handler prompt could have been obscured using a data: URL within
The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-12329P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.12
CVE-2026-12329 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12329
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12329
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12308P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.12
CVE-2026-12308 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12308
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12308
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12306P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.12
CVE-2026-12306 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12306
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12306
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12307P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.12
CVE-2026-12307 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12307
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12307
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-6767P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.10
CVE-2026-6767 [MEDIUM] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6767
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6767
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-6765P4MEDIUMCVSS 5.3fixed in Firefox ESR 140.10
CVE-2026-6765 [MEDIUM] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6765
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6765
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla