cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 42 of 45
CVE-2018-12383P4MEDIUMCVSS 5.5fixed in 60.2.1≥ unspecified, < 60.2.12018-10-18
CVE-2018-12383 [MEDIUM] CWE-522 CVE-2018-12383: If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted cop If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the expos
nvd
CVE-2017-5409P4MEDIUMCVSS 5.5≥ unspecified, < 45.82018-06-11
CVE-2017-5409 [MEDIUM] CWE-269 CVE-2017-5409: The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerabil
nvd
CVE-2017-7768P4MEDIUMCVSS 5.5≥ unspecified, < 52.22018-06-11
CVE-2017-7768 [MEDIUM] CWE-200 CVE-2017-7768: The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbit The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. N
nvd
CVE-2017-7767P4MEDIUMCVSS 5.5≥ unspecified, < 52.22018-06-11
CVE-2017-7767 [MEDIUM] CWE-269 CVE-2017-7767: The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects F
nvd
CVE-2022-36318P4MEDIUMCVSS 5.3fixed in 102.1fixed in 91.12+2 more2022-12-22
CVE-2022-36318 [MEDIUM] CWE-362 CVE-2022-36318: When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
nvd
CVE-2021-38509P4MEDIUMCVSS 4.3fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38509 [MEDIUM] CWE-1021 CVE-2021-38509: Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2019-11715P4MEDIUMCVSS 6.1≥ unspecified, < 60.82019-07-23
CVE-2019-11715 [MEDIUM] CWE-79 CVE-2019-11715: Due to an error while parsing page content, it is possible for properly sanitized user input to be m Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2019-11763P4MEDIUMCVSS 6.1fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11763 [MEDIUM] CWE-79 CVE-2019-11763: Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of e
nvd
CVE-2020-12405P4MEDIUMCVSS 5.3fixed in 68.9.0≥ unspecified, < 68.92020-07-09
CVE-2020-12405 [MEDIUM] CWE-362 CVE-2020-12405: When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2020-15649P4MEDIUMCVSS 5.5fixed in 68.11≥ unspecified, < 68.112020-08-10
CVE-2020-15649 [MEDIUM] CWE-434 CVE-2020-15649: Given an installed malicious file picker application, an attacker was able to steal and upload local Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of the actually files picked. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
nvd
CVE-2017-7782P4MEDIUMCVSS 5.3≥ unspecified, < 52.32018-06-11
CVE-2017-7782 [MEDIUM] CWE-269 CVE-2017-7782: An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated b An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
nvd
CVE-2016-5294P4MEDIUMCVSS 5.5≥ unspecified, < 45.52018-06-11
CVE-2016-5294 [MEDIUM] CWE-20 CVE-2016-5294: The Mozilla Updater can be made to choose an arbitrary target working directory for output files res The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
CVE-2019-9817P4MEDIUMCVSS 5.3fixed in 60.7≥ unspecified, < 60.72019-07-23
CVE-2019-9817 [MEDIUM] CWE-346 CVE-2019-9817: Images from a different domain can be read using a canvas object in some circumstances. This could b Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2026-12311P4MEDIUMCVSS 4.7fixed in Firefox ESR 140.12
CVE-2026-12311 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12311 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12311 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-15718P4MEDIUMCVSS 4.3fixed in Firefox ESR 140.13
CVE-2026-15718 [MEDIUM] Mozilla Foundation Security Advisory 2026-70: CVE-2026-15718 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-15718 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2016-5293P4MEDIUMCVSS 5.5≥ unspecified, < 45.52018-06-11
CVE-2016-5293 [MEDIUM] CWE-20 CVE-2016-5293: When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hard When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.
nvd
CVE-2017-7761P4MEDIUMCVSS 5.5≥ unspecified, < 52.22018-06-11
CVE-2017-7761 [MEDIUM] CWE-276 CVE-2017-7761: The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by n The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with creation of a junction (a form of symbolic link), protected files in the target directory of the junction can be deleted by the Mozilla Maintenance Service, which has privileged access. Note: This attack r
nvd
CVE-2023-4054P4MEDIUMCVSS 5.5≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4054 [MEDIUM] CVE-2023-4054: When opening appref-ms files, Firefox did not warn the user that these files may contain malicious c When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102.14, Firefox ESR < 115.1, Thunderbird < 102.14, and Thunderbird < 115.1.
nvd
CVE-2024-5691P4MEDIUMCVSS 4.7fixed in 115.12≥ unspecified, < 115.122024-06-11
CVE-2024-5691 [MEDIUM] CWE-693 CVE-2024-5691: By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a b By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2020-6797P4MEDIUMCVSS 4.3fixed in 68.5.02020-03-02
CVE-2020-6797 [MEDIUM] CWE-20 CVE-2020-6797: By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbit By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating sy
nvd
Mozilla Firefox Esr vulnerabilities | cvebase