cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 43 of 49
CVE-2019-11761P4MEDIUMCVSS 5.4fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11761 [MEDIUM] CWE-362 CVE-2019-11761: By using a form with a data URI it was possible to gain access to the privileged JSONView object tha By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2023-4045P4MEDIUMCVSS 5.3≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4045 [MEDIUM] CWE-346 CVE-2023-4045: Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2024-11696P4MEDIUMCVSS 5.4≥ unspecified, < 128.52024-11-26
CVE-2024-11696 [MEDIUM] CWE-347 CVE-2024-11696: The application failed to account for exceptions thrown by the `loadManifestFromFile` method during The application failed to account for exceptions thrown by the `loadManifestFromFile` method during add-on signature verification. This flaw, triggered by an invalid or unsupported extension manifest, could have caused runtime errors that disrupted the signature validation process. As a result, the enforcement of signature validation for unrelated ad
nvd
CVE-2026-12298P4MEDIUMCVSS 5.4fixed in Firefox ESR 140.12
CVE-2026-12298 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12298 Mozilla Foundation Security Advisory 2026-58 CVE: CVE-2026-12298 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.12
mozilla
CVE-2026-84120P4MEDIUMCVSS 5.4fixed in Firefox ESR 153.2
CVE-2026-84120 [MEDIUM] Mozilla Foundation Security Advisory 2026-85: CVE-2026-84120 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84120 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2026-84122P4MEDIUMCVSS 5.4fixed in Firefox ESR 140.15
CVE-2026-84122 [MEDIUM] Mozilla Foundation Security Advisory 2026-84: CVE-2026-84122 Mozilla Foundation Security Advisory 2026-84 CVE: CVE-2026-84122 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.15
mozilla
CVE-2026-84124P4MEDIUMCVSS 5.4fixed in Firefox ESR 153.2
CVE-2026-84124 [MEDIUM] Mozilla Foundation Security Advisory 2026-85: CVE-2026-84124 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84124 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2026-8391P4MEDIUMCVSS 5.3fixed in Firefox ESR 115.36
CVE-2026-8391 [MEDIUM] Mozilla Foundation Security Advisory 2026-47: CVE-2026-8391 Mozilla Foundation Security Advisory 2026-47 CVE: CVE-2026-8391 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.36
mozilla
CVE-2026-84136P4UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84136 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84136 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84136 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2014-8638P4MEDIUMCVSS 6.8v31.22015-01-14
CVE-2014-8638 [MEDIUM] CWE-352 CVE-2014-8638: The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4 The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.
nvd
CVE-2019-17022P4MEDIUMCVSS 6.1fixed in 68.4vbefore 68.42020-01-08
CVE-2019-17022 [MEDIUM] CWE-79 CVE-2019-17022: When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does When pasting a tag from the clipboard into a rich text editor, the CSS sanitizer does not escape characters. Because the resulting string is pasted directly into the text node of the element this does not result in a direct injection into the webpage; however, if a webpage subsequently copies the node's innerHTML, assigning it to another innerHTML, th
nvd
CVE-2022-40956P4MEDIUMCVSS 6.1fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-40956 [MEDIUM] CWE-79 CVE-2022-40956: When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and acce When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2022-45418P4MEDIUMCVSS 6.1fixed in 102.5≥ unspecified, < 102.52022-12-22
CVE-2022-45418 [MEDIUM] CWE-1021 CVE-2022-45418: If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been If a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
nvd
CVE-2022-29912P4MEDIUMCVSS 6.1fixed in 91.9≥ unspecified, < 91.92022-12-22
CVE-2022-29912 [MEDIUM] CWE-601 CVE-2022-29912: Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This Requests initiated through reader mode did not properly omit cookies with a SameSite attribute. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
nvd
CVE-2019-11762P4MEDIUMCVSS 6.1fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11762 [MEDIUM] CWE-346 CVE-2019-11762: If two same-origin documents set document.domain differently to become cross-origin, it was possible If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2017-5408P4MEDIUMCVSS 5.3≥ unspecified, < 45.82018-06-11
CVE-2017-5408 [MEDIUM] CWE-200 CVE-2017-5408: Video files loaded video captions cross-origin without checking for the presence of CORS headers per Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2017-5405P4MEDIUMCVSS 5.3≥ unspecified, < 45.82018-06-11
CVE-2017-5405 [MEDIUM] CWE-1187 CVE-2017-5405: Certain response codes in FTP connections can result in the use of uninitialized values for ports in Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
nvd
CVE-2024-8386P4MEDIUMCVSS 6.1fixed in 128.2≥ unspecified, < 128.22024-09-03
CVE-2024-8386 [MEDIUM] CWE-601 CVE-2024-8386: If a site had been granted the permission to open popup windows, it could cause Select elements to a If a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform a spoofing attack. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvd
CVE-2018-5117P4MEDIUMCVSS 5.3≥ unspecified, < 52.62018-06-11
CVE-2018-5117 [MEDIUM] CVE-2018-5117: If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spoof the displayed URL. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded. This vulnerability affects Thunderbird <
nvd
CVE-2018-5168P4MEDIUMCVSS 5.3≥ unspecified, < 52.82018-06-11
CVE-2018-5168 [MEDIUM] CVE-2018-5168: Sites can bypass security checks on permissions to install lightweight themes by manipulating the "b Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and F
nvd
Mozilla Firefox Esr vulnerabilities | cvebase