cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 45 of 45
CVE-2024-3861P4MEDIUMCVSS 4.0≥ unspecified, < 115.102024-04-16
CVE-2024-3861 [MEDIUM] CWE-416 CVE-2024-3861: If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect r If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2019-11743P4LOWCVSS 3.7≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11743 [LOW] CWE-203 CVE-2019-11743: Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specificati Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affect
nvd
CVE-2024-3302P4LOWCVSS 3.7≥ unspecified, < 115.102024-04-16
CVE-2024-3302 [LOW] CWE-770 CVE-2024-3302: There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server cou There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2023-34414P4LOWCVSS 3.1fixed in 102.12≥ unspecified, < 102.122023-06-19
CVE-2023-34414 [LOW] CWE-295 CVE-2023-34414: The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks that exploit human response time delays. If a malicious page elicited user clicks in precise locations immediately before navigating to a site with a certificate error and made the renderer extremel
nvd
CVE-2024-2616P4LOWCVSS 2.7≥ unspecified, < 115.92024-03-19
CVE-2024-2616 [LOW] CWE-787 CVE-2024-2616: To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash i To harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnerability affects Firefox ESR < 115.9 and Thunderbird < 115.9.
nvd
CVE-2014-1595P4LOWCVSS 2.1v31.22014-12-11
CVE-2014-1595 [LOW] CWE-199 CVE-2014-1595: Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase