Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 43 of 45
CVE-2024-6601P4MEDIUMCVSS 4.7≥ unspecified, < 115.132024-07-09
CVE-2024-6601 [MEDIUM] CWE-367 CVE-2024-6601: A race condition could lead to a cross-origin container obtaining permissions of the top-level origi
A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2026-12313P4MEDIUMCVSS 4.7fixed in Firefox ESR 140.12
CVE-2026-12313 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12313
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12313
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2020-15650P4MEDIUMCVSS 5.5fixed in 68.11≥ unspecified, < 68.112020-08-10
CVE-2020-15650 [MEDIUM] CVE-2020-15650: Given an installed malicious file picker application, an attacker was able to overwrite local files
Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (but not access the previous profile). *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.11.
nvd
CVE-2022-36314P4MEDIUMCVSS 5.5fixed in 102.1≥ unspecified, < 102.12022-12-22
CVE-2022-36314 [MEDIUM] CWE-427 CVE-2022-36314: When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path th
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.
nvd
CVE-2015-0827P4MEDIUMCVSS 4.3v31.1v31.2+3 more2015-02-25
CVE-2015-0827 [MEDIUM] CWE-119 CVE-2015-0827: Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Fi
Heap-based buffer overflow in the mozilla::gfx::CopyRect function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to obtain sensitive information from uninitialized process memory via a malformed SVG graphic.
nvd
CVE-2024-1548P4MEDIUMCVSS 4.3≥ unspecified, < 115.82024-02-20
CVE-2024-1548 [MEDIUM] CVE-2024-1548: A website could have obscured the fullscreen notification by using a dropdown select input element.
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2023-5725P4MEDIUMCVSS 4.3fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5725 [MEDIUM] CVE-2023-5725: A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance cou
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2024-5690P4MEDIUMCVSS 4.3fixed in 115.12≥ unspecified, < 115.122024-06-11
CVE-2024-5690 [MEDIUM] CWE-203 CVE-2024-5690: By monitoring the time certain operations take, an attacker could have guessed which external protoc
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2024-11692P4MEDIUMCVSS 4.3≥ unspecified, < 128.52024-11-26
CVE-2024-11692 [MEDIUM] CWE-290 CVE-2024-11692: An attacker could cause a select dropdown to be shown over another tab; this could have led to user
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2021-38508P4MEDIUMCVSS 4.3fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38508 [MEDIUM] CWE-1021 CVE-2021-38508: By displaying a form validity message in the correct location at the same time as a permission promp
By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially being tricked into granting the permission. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2021-38506P4MEDIUMCVSS 4.3fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38506 [MEDIUM] CWE-1021 CVE-2021-38506: Through a series of navigations, Firefox could have entered fullscreen mode without notification or
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2020-26953P4MEDIUMCVSS 4.3fixed in 78.52020-12-09
CVE-2020-26953 [MEDIUM] CWE-1021 CVE-2020-26953: It was possible to cause the browser to enter fullscreen mode without displaying the security UI; th
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2020-35111P4MEDIUMCVSS 4.3fixed in 78.6.0≥ unspecified, < 78.62021-01-07
CVE-2020-35111 [MEDIUM] CVE-2020-35111: When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest ca
When an extension with the proxy permission registered to receive , the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.
nvd
CVE-2021-43538P4MEDIUMCVSS 4.3fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43538 [MEDIUM] CWE-362 CVE-2021-43538: By misusing a race in our notification code, an attacker could have forcefully hidden the notificati
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2019-11749P4MEDIUMCVSS 4.3fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11749 [MEDIUM] CVE-2019-11749: A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUs
A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
nvd
CVE-2023-5721P4MEDIUMCVSS 4.3fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5721 [MEDIUM] CWE-1021 CVE-2023-5721: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2022-22743P4MEDIUMCVSS 4.3fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22743 [MEDIUM] CVE-2022-22743: When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab
When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2024-0742P4MEDIUMCVSS 4.3fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0742 [MEDIUM] CVE-2024-0742: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2022-34472P4MEDIUMCVSS 4.3fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-34472 [MEDIUM] CWE-703 CVE-2022-34472: If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would
If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2023-4581P4MEDIUMCVSS 4.3fixed in 102.15≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4581 [MEDIUM] CVE-2023-4581: Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which all
Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
nvd