Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 45 of 49
CVE-2020-12392P4MEDIUMCVSS 5.5fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-12392 [MEDIUM] CWE-22 CVE-2020-12392: The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and
nvd
CVE-2022-28286P4MEDIUMCVSS 5.4fixed in 91.8≥ unspecified, < 91.82022-12-22
CVE-2022-28286 [MEDIUM] CWE-1021 CVE-2022-28286: Due to a layout change, iframe contents could have been rendered outside of its border. This could h
Due to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.
nvd
CVE-2023-29532P4MEDIUMCVSS 5.5fixed in 102.10≥ unspecified, < 102.102023-06-19
CVE-2023-29532 [MEDIUM] CVE-2023-29532: A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by
A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server.
*Note: This attack requires local syste
nvd
CVE-2023-6857P4MEDIUMCVSS 5.3fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6857 [MEDIUM] CWE-362 CVE-2023-6857: When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be sma
When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary.
*This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2026-12299P4MEDIUMCVSS 5.4fixed in Firefox ESR 140.12
CVE-2026-12299 [MEDIUM] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12299
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12299
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2015-0822P4MEDIUMCVSS 4.3v31.1v31.2+3 more2015-02-25
CVE-2015-0822 [MEDIUM] CWE-200 CVE-2015-0822: The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Th
The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code.
nvd
CVE-2026-74974P4UNKNOWNfixed in Firefox ESR 115.39
CVE-2026-74974 Mozilla Foundation Security Advisory 2026-75: CVE-2026-74974
Mozilla Foundation Security Advisory 2026-75
CVE: CVE-2026-74974
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.39
mozilla
CVE-2026-74963P4UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74963 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74963
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74963
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2015-2729P4MEDIUMCVSS 5.0v31.1v31.2+5 more2015-07-06
CVE-2015-2729 [MEDIUM] CWE-119 CVE-2015-2729: The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Fire
The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before 38.1 does not properly calculate an oscillator rendering range, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecifi
nvd
CVE-2018-12383P4MEDIUMCVSS 5.5fixed in 60.2.1≥ unspecified, < 60.2.12018-10-18
CVE-2018-12383 [MEDIUM] CWE-522 CVE-2018-12383: If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted cop
If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the expos
nvd
CVE-2017-5409P4MEDIUMCVSS 5.5≥ unspecified, < 45.82018-06-11
CVE-2017-5409 [MEDIUM] CWE-269 CVE-2017-5409: The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerabil
nvd
CVE-2017-7768P4MEDIUMCVSS 5.5≥ unspecified, < 52.22018-06-11
CVE-2017-7768 [MEDIUM] CWE-200 CVE-2017-7768: The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbit
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. N
nvd
CVE-2023-25730P4MEDIUMCVSS 5.4fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25730 [MEDIUM] CWE-1021 CVE-2023-25730: A background script invoking <code>requestFullscreen</code> and then blocking the main thread could
A background script invoking requestFullscreen and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2017-7767P4MEDIUMCVSS 5.5≥ unspecified, < 52.22018-06-11
CVE-2017-7767 [MEDIUM] CWE-269 CVE-2017-7767: The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects F
nvd
CVE-2022-36318P4MEDIUMCVSS 5.3fixed in 102.1fixed in 91.12+2 more2022-12-22
CVE-2022-36318 [MEDIUM] CWE-362 CVE-2022-36318: When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.
nvd
CVE-2021-38509P4MEDIUMCVSS 4.3fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38509 [MEDIUM] CWE-1021 CVE-2021-38509: Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary
Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2026-74970P4UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74970 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74970
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74970
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74967P4UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74967 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74967
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74967
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74968P4UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74968 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74968
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74968
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2019-11715P4MEDIUMCVSS 6.1≥ unspecified, < 60.82019-07-23
CVE-2019-11715 [MEDIUM] CWE-79 CVE-2019-11715: Due to an error while parsing page content, it is possible for properly sanitized user input to be m
Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
nvd