cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 42 of 49
CVE-2015-0807P4MEDIUMCVSS 6.8v31.1v31.2+3 more2015-04-01
CVE-2015-0807 [MEDIUM] CVE-2015-0807: The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6 The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted w
nvd
CVE-2021-23973P4MEDIUMCVSS 6.5fixed in 78.82021-02-26
CVE-2021-23973 [MEDIUM] CWE-209 CVE-2021-23973: When trying to load a cross-origin resource in an audio/video context a decoding error may have resu When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2020-6798P4MEDIUMCVSS 6.1fixed in 68.5.02020-03-02
CVE-2020-6798 [MEDIUM] CWE-79 CVE-2020-6798: If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsin If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly could suffer a cross-site scripting vulnerability as a result. In general, this flaw cannot be exploited through email in the Thunderbird product because
nvd
CVE-2022-42929P4MEDIUMCVSS 6.5fixed in 102.4≥ unspecified, < 102.42022-12-22
CVE-2022-42929 [MEDIUM] CWE-400 CVE-2022-42929: If a website called `window.print()` in a particular way, it could cause a denial of service of the If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.
nvd
CVE-2020-15677P4MEDIUMCVSS 6.1fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15677 [MEDIUM] CWE-601 CVE-2020-15677: By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site d By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2023-4578P4MEDIUMCVSS 6.5fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4578 [MEDIUM] CWE-770 CVE-2023-4578: When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling ` When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a newly created Out of Memory exception to be mishandled as a Syntax Error. This vulnerability affects Firefox < 117,
nvd
CVE-2020-15676P4MEDIUMCVSS 6.1fixed in 78.3≥ unspecified, < 78.32020-10-01
CVE-2020-15676 [MEDIUM] CWE-79 CVE-2020-15676: Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
nvd
CVE-2020-26958P4MEDIUMCVSS 6.1fixed in 78.52020-12-09
CVE-2020-26958 [MEDIUM] CWE-79 CVE-2020-26958: Firefox did not block execution of scripts with incorrect MIME types when the response was intercept Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2020-26951P4MEDIUMCVSS 6.1fixed in 78.52020-12-09
CVE-2020-26951 [MEDIUM] CWE-79 CVE-2020-26951: A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, e A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to bypass our built-in sanitizer. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbi
nvd
CVE-2017-5462P4MEDIUMCVSS 5.3≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5462 [MEDIUM] CWE-682 CVE-2017-5462: A flaw in DRBG number generation within the Network Security Services (NSS) library where the intern A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Fir
nvd
CVE-2022-45411P4MEDIUMCVSS 6.1fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45411 [MEDIUM] CWE-79 CVE-2022-45411: Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an X Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on fetch() and XMLHttpRequest; however some webservers have implemented non-sta
nvd
CVE-2024-10461P4MEDIUMCVSS 6.1≥ unspecified, < 128.42024-10-29
CVE-2024-10461 [MEDIUM] CWE-79 CVE-2024-10461: In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2022-29911P4MEDIUMCVSS 6.1fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29911 [MEDIUM] CWE-1021 CVE-2022-29911: An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-acti An improper implementation of the new iframe sandbox keyword allow-top-navigation-by-user-activation could lead to script execution without allow-scripts being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2024-4768P4MEDIUMCVSS 6.1≥ unspecified, < 115.112024-05-14
CVE-2024-4768 [MEDIUM] CWE-281 CVE-2024-4768: A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a us A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2024-1549P4MEDIUMCVSS 6.1≥ unspecified, < 115.82024-02-20
CVE-2024-1549 [MEDIUM] CVE-2024-1549: If a website set a large custom cursor, portions of the cursor could have overlapped with the permis If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2016-9064P4MEDIUMCVSS 5.9≥ unspecified, < 45.52018-06-11
CVE-2016-9064 [MEDIUM] CWE-295 CVE-2016-9064: Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the a Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinning protection could provide a malicious signed add-on instead of a valid update. This vulnerabili
nvd
CVE-2024-11694P4MEDIUMCVSS 6.1≥ unspecified, < 128.5≥ unspecified, < 115.182024-11-26
CVE-2024-11694 [MEDIUM] CWE-79 CVE-2024-11694: Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass a Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ES
nvd
CVE-2024-7524P4MEDIUMCVSS 6.1fixed in 115.14≥ 116.0, < 128.1+2 more2024-08-06
CVE-2024-7524 [MEDIUM] CWE-79 CVE-2024-7524: Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM Clobbering attack on some of the shims and achieved XSS, bypassing the CSP strict-dynamic protection. Thi
nvd
CVE-2017-7825P4MEDIUMCVSS 5.3≥ unspecified, < 52.42018-06-11
CVE-2017-7825 [MEDIUM] CWE-20 CVE-2017-7825: Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the add Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.
nvd
CVE-2024-2611P4MEDIUMCVSS 5.5≥ unspecified, < 115.92024-03-19
CVE-2024-2611 [MEDIUM] CVE-2024-2611: A missing delay on when pointer lock was used could have allowed a malicious page to trick a user in A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase