Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 41 of 45
CVE-2024-9398P4MEDIUMCVSS 5.3fixed in 128.3.0≥ unspecified, < 128.32024-10-01
CVE-2024-9398 [MEDIUM] CWE-203 CVE-2024-9398: By checking the result of calls to `window.open` with specifically set protocol handlers, an attacke
By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2026-12299P4MEDIUMCVSS 5.4fixed in Firefox ESR 140.12
CVE-2026-12299 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12299
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12299
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-12330P4MEDIUMCVSS 5.4fixed in Firefox ESR 115.37
CVE-2026-12330 [MEDIUM] Mozilla Foundation Security Advisory 2026-59: CVE-2026-12330
Mozilla Foundation Security Advisory 2026-59
CVE: CVE-2026-12330
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.37
mozilla
CVE-2016-9895P4MEDIUMCVSS 6.1≥ unspecified, < 45.62018-06-11
CVE-2016-9895 [MEDIUM] CWE-254 CVE-2016-9895: Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) th
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-5466P4MEDIUMCVSS 6.1≥ unspecified, < 52.12018-06-11
CVE-2017-5466 [MEDIUM] CWE-79 CVE-2017-5466: If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:tex
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2019-11744P4MEDIUMCVSS 6.1≥ unspecified, < 60.9≥ unspecified, < 68.12019-09-27
CVE-2019-11744 [MEDIUM] CWE-79 CVE-2019-11744: Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets w
Some HTML elements, such as and , can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as
nvd
CVE-2021-43543P4MEDIUMCVSS 6.1fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43543 [MEDIUM] CWE-79 CVE-2021-43543: Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-26956P4MEDIUMCVSS 6.1fixed in 78.52020-12-09
CVE-2020-26956 [MEDIUM] CWE-79 CVE-2020-26956: In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and
In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2017-5383P4MEDIUMCVSS 5.3≥ unspecified, < 45.72018-06-11
CVE-2017-5383 [MEDIUM] CWE-20 CVE-2017-5383: URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger pu
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2019-9801P4MEDIUMCVSS 5.3fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9801 [MEDIUM] CWE-20 CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch th
Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. O
nvd
CVE-2023-4046P4MEDIUMCVSS 5.3≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4046 [MEDIUM] CWE-770 CVE-2023-4046: In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis
In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2016-5291P4MEDIUMCVSS 5.5≥ unspecified, < 45.52018-06-11
CVE-2016-5291 [MEDIUM] CWE-20 CVE-2016-5291: A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. Thi
A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2020-12392P4MEDIUMCVSS 5.5fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12392 [MEDIUM] CWE-22 CVE-2020-12392: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and
nvd
CVE-2022-28286P4MEDIUMCVSS 5.4fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28286 [MEDIUM] CWE-1021 CVE-2022-28286: Due to a layout change, iframe contents could have been rendered outside of its border. This could h
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvd
CVE-2023-25730P4MEDIUMCVSS 5.4fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25730 [MEDIUM] CWE-1021 CVE-2023-25730: A background script invoking <code>requestFullscreen</code> and then blocking the main thread could
A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2023-29532P4MEDIUMCVSS 5.5fixed in 102.10≥ unspecified, < 102.102023-06-19
CVE-2023-29532 [MEDIUM] CVE-2023-29532: A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.
*Note: This attack requires local syste
nvd
CVE-2023-6857P4MEDIUMCVSS 5.3fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6857 [MEDIUM] CWE-362 CVE-2023-6857: When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be sma
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary.
*This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2015-0822P4MEDIUMCVSS 4.3v31.1v31.2+3 more2015-02-25
CVE-2015-0822 [MEDIUM] CWE-200 CVE-2015-0822: The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Th
The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code.
nvd
CVE-2015-2729P4MEDIUMCVSS 5.0v31.1v31.2+5 more2015-07-06
CVE-2015-2729 [MEDIUM] CWE-119 CVE-2015-2729: The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Fire
The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before 38.1 does not properly calculate an oscillator rendering range, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecifi
nvd
CVE-2017-7823P4MEDIUMCVSS 5.4≥ unspecified, < 52.42018-06-11
CVE-2017-7823 [MEDIUM] CWE-79 CVE-2017-7823: The content security policy (CSP) "sandbox" directive did not create a unique origin for the documen
The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 5
nvd