Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 45 of 45
CVE-2024-3861P4MEDIUMCVSS 4.0≥ unspecified, < 115.102024-04-16
CVE-2024-3861 [MEDIUM] CWE-416 CVE-2024-3861: If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect r
If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2019-11743P4LOWCVSS 3.7≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11743 [LOW] CWE-203 CVE-2019-11743: Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specificati
Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affect
nvd
CVE-2024-3302P4LOWCVSS 3.7≥ unspecified, < 115.102024-04-16
CVE-2024-3302 [LOW] CWE-770 CVE-2024-3302: There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server cou
There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2023-34414P4LOWCVSS 3.1fixed in 102.12≥ unspecified, < 102.122023-06-19
CVE-2023-34414 [LOW] CWE-295 CVE-2023-34414: The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses
The error page for sites with invalid TLS certificates was missing the
activation-delay Firefox uses to protect prompts and permission dialogs
from attacks that exploit human response time delays. If a malicious
page elicited user clicks in precise locations immediately before
navigating to a site with a certificate error and made the renderer
extremel
nvd
CVE-2024-2616P4LOWCVSS 2.7≥ unspecified, < 115.92024-03-19
CVE-2024-2616 [LOW] CWE-787 CVE-2024-2616: To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash i
To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR < 115.9 and Thunderbird < 115.9.
nvd
CVE-2014-1595P4LOWCVSS 2.1v31.22014-12-11
CVE-2014-1595 [LOW] CWE-199 CVE-2014-1595: Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
nvd
← Previous45 / 45