Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 44 of 45
CVE-2022-3266P4MEDIUMCVSS 5.5fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-3266 [MEDIUM] CWE-125 CVE-2022-3266: An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2012-0451P4MEDIUMCVSS 4.3v10.1v10.22012-03-14
CVE-2012-0451 [MEDIUM] CWE-94 CVE-2012-0451: CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Th
CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP head
nvd
CVE-2018-12367P4MEDIUMCVSS 4.3≥ unspecified, < 60.12018-10-18
CVE-2018-12367 [MEDIUM] CWE-20 CVE-2018-12367: In the previous mitigations for Spectre, the resolution or precision of various methods was reduced
In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Fire
nvd
CVE-2021-43546P4MEDIUMCVSS 4.3fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43546 [MEDIUM] CWE-1021 CVE-2021-43546: It was possible to recreate previous cursor spoofing attacks against users with a zoomed native curs
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2015-2741P4MEDIUMCVSS 4.3v31.1v31.2+5 more2015-07-06
CVE-2015-2741 [MEDIUM] CWE-310 CVE-2015-2741: Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforc
Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname f
nvd
CVE-2021-23969P4MEDIUMCVSS 4.3fixed in 78.82021-02-26
CVE-2021-23969 [MEDIUM] CVE-2021-23969: As specified in the W3C Content Security Policy draft, when creating a violation report, "User agent
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the s
nvd
CVE-2021-23953P4MEDIUMCVSS 4.3fixed in 78.72021-02-26
CVE-2021-23953 [MEDIUM] CVE-2021-23953: If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cro
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvd
CVE-2015-0833P4MEDIUMCVSS 6.9v31.1v31.2+3 more2015-02-25
CVE-2015-0833 [MEDIUM] CVE-2015-0833: Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefo
Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dl
nvd
CVE-2022-26383P4MEDIUMCVSS 4.3fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26383 [MEDIUM] CWE-451 CVE-2022-26383: When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvd
CVE-2023-32212P4MEDIUMCVSS 4.3fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32212 [MEDIUM] CVE-2023-32212: An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerabilit
An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2023-32205P4MEDIUMCVSS 4.3fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32205 [MEDIUM] CVE-2023-32205: In multiple cases browser prompts could have been obscured by popups controlled by content. These co
In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2023-5726P4MEDIUMCVSS 4.3fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5726 [MEDIUM] CVE-2023-5726: A website could have obscured the full screen notification by using the file open dialog. This could
A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks.
*Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2023-29533P4MEDIUMCVSS 4.3fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29533 [MEDIUM] CVE-2023-29533: A website could have obscured the fullscreen notification by using a combination of <code>window.ope
A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thun
nvd
CVE-2024-4767P4MEDIUMCVSS 4.3≥ unspecified, < 115.112024-05-14
CVE-2024-4767 [MEDIUM] CWE-459 CVE-2024-4767: If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2012-0455P4MEDIUMCVSS 4.3v10.1v10.22012-03-14
CVE-2012-0455 [MEDIUM] CWE-79 CVE-2012-0455: Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird befo
Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2020-6827P4MEDIUMCVSS 4.7fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6827 [MEDIUM] CWE-1021 CVE-2020-6827: When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firef
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
nvd
CVE-2017-5451P4MEDIUMCVSS 4.3≥ unspecified, < 52.12018-06-11
CVE-2017-5451 [MEDIUM] CWE-20 CVE-2017-5451: A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur"
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2020-12399P4MEDIUMCVSS 4.4fixed in 68.9.0≥ unspecified, < 68.92020-07-09
CVE-2020-12399 [MEDIUM] CWE-203 CVE-2020-12399: NSS has shown timing differences when performing DSA signatures, which was exploitable and could eve
NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2024-0749P4MEDIUMCVSS 4.3fixed in 115.72024-01-23
CVE-2024-0749 [MEDIUM] CWE-346 CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect
A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
nvd
CVE-2021-23968P4MEDIUMCVSS 4.3fixed in 78.82021-02-26
CVE-2021-23968 [MEDIUM] CWE-209 CVE-2021-23968: If Content Security Policy blocked frame navigation, the full destination of a redirect served in th
If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd