cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 44 of 49
CVE-2019-11717P4MEDIUMCVSS 5.3≥ unspecified, < 60.82019-07-23
CVE-2019-11717 [MEDIUM] CWE-116 CVE-2019-11717: A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd
CVE-2017-7764P4MEDIUMCVSS 5.3≥ unspecified, < 52.22018-06-11
CVE-2017-7764 [MEDIUM] CWE-20 CVE-2017-7764: Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unico Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. The current Unicode standard allows characters from "Aspirational Use Scripts" such as Canadian Syl
nvd
CVE-2019-17021P4MEDIUMCVSS 5.3fixed in 68.4vbefore 68.42020-01-08
CVE-2019-17021 [MEDIUM] CWE-362 CVE-2019-17021: During the initialization of a new content process, a race condition occurs that can allow a content During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2018-12381P4MEDIUMCVSS 5.3≥ unspecified, < 60.22018-10-18
CVE-2018-12381 [MEDIUM] CWE-610 CVE-2018-12381: Manually dragging and dropping an Outlook email message into the browser will trigger a page navigat Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Fi
nvd
CVE-2017-7763P4MEDIUMCVSS 5.3≥ unspecified, < 52.22018-06-11
CVE-2017-7763 [MEDIUM] CWE-20 CVE-2017-7763: Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2023-6206P4MEDIUMCVSS 5.4fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6206 [MEDIUM] CWE-1021 CVE-2023-6206: The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking dela The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2024-11695P4MEDIUMCVSS 5.4≥ unspecified, < 128.52024-11-26
CVE-2024-11695 [MEDIUM] CWE-1021 CVE-2024-11695: A crafted URL containing Arabic script and whitespace characters could have hidden the true origin o A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2024-9398P4MEDIUMCVSS 5.3fixed in 128.3.0≥ unspecified, < 128.32024-10-01
CVE-2024-9398 [MEDIUM] CWE-203 CVE-2024-9398: By checking the result of calls to `window.open` with specifically set protocol handlers, an attacke By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2026-12330P4MEDIUMCVSS 5.4fixed in Firefox ESR 115.37
CVE-2026-12330 [MEDIUM] Mozilla Foundation Security Advisory 2026-59: CVE-2026-12330 Mozilla Foundation Security Advisory 2026-59 CVE: CVE-2026-12330 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.37
mozilla
CVE-2026-84139P4UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84139 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84139 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84139 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2016-9895P4MEDIUMCVSS 6.1≥ unspecified, < 45.62018-06-11
CVE-2016-9895 [MEDIUM] CWE-254 CVE-2016-9895: Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) th Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2017-5466P4MEDIUMCVSS 6.1≥ unspecified, < 52.12018-06-11
CVE-2017-5466 [MEDIUM] CWE-79 CVE-2017-5466: If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:tex If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2019-11744P4MEDIUMCVSS 6.1≥ unspecified, < 60.9≥ unspecified, < 68.12019-09-27
CVE-2019-11744 [MEDIUM] CWE-79 CVE-2019-11744: Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets w Some HTML elements, such as and , can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will be parsed as if it were outside the tag. This can lead to XSS if a site does not filter user input as strictly for these elements as
nvd
CVE-2021-43543P4MEDIUMCVSS 6.1fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43543 [MEDIUM] CWE-79 CVE-2021-43543: Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2020-26956P4MEDIUMCVSS 6.1fixed in 78.52020-12-09
CVE-2020-26956 [MEDIUM] CWE-79 CVE-2020-26956: In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2017-5383P4MEDIUMCVSS 5.3≥ unspecified, < 45.72018-06-11
CVE-2017-5383 [MEDIUM] CWE-20 CVE-2017-5383: URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger pu URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2017-7823P4MEDIUMCVSS 5.4≥ unspecified, < 52.42018-06-11
CVE-2017-7823 [MEDIUM] CWE-79 CVE-2017-7823: The content security policy (CSP) "sandbox" directive did not create a unique origin for the documen The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allow-same-origin" keyword were always specified. This could allow a Cross-Site Scripting (XSS) attack to be launched from unsafe content. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 5
nvd
CVE-2019-9801P4MEDIUMCVSS 5.3fixed in 60.6≥ unspecified, < 60.62019-04-26
CVE-2019-9801 [MEDIUM] CWE-20 CVE-2019-9801: Firefox will accept any registered Program ID as an external protocol handler and offer to launch th Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. O
nvd
CVE-2023-4046P4MEDIUMCVSS 5.3≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4046 [MEDIUM] CWE-770 CVE-2023-4046: In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2016-5291P4MEDIUMCVSS 5.5≥ unspecified, < 45.52018-06-11
CVE-2016-5291 [MEDIUM] CWE-20 CVE-2016-5291: A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. Thi A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase