Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 47 of 49
CVE-2024-1548P4MEDIUMCVSS 4.3≥ unspecified, < 115.82024-02-20
CVE-2024-1548 [MEDIUM] CVE-2024-1548: A website could have obscured the fullscreen notification by using a dropdown select input element.
A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.
nvd
CVE-2023-5725P4MEDIUMCVSS 4.3fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5725 [MEDIUM] CVE-2023-5725: A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance cou
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2024-5690P4MEDIUMCVSS 4.3fixed in 115.12≥ unspecified, < 115.122024-06-11
CVE-2024-5690 [MEDIUM] CWE-203 CVE-2024-5690: By monitoring the time certain operations take, an attacker could have guessed which external protoc
By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2024-11692P4MEDIUMCVSS 4.3≥ unspecified, < 128.52024-11-26
CVE-2024-11692 [MEDIUM] CWE-290 CVE-2024-11692: An attacker could cause a select dropdown to be shown over another tab; this could have led to user
An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2021-38506P4MEDIUMCVSS 4.3fixed in 91.3.0≥ unspecified, < 91.32021-12-08
CVE-2021-38506 [MEDIUM] CWE-1021 CVE-2021-38506: Through a series of navigations, Firefox could have entered fullscreen mode without notification or
Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.
nvd
CVE-2020-26953P4MEDIUMCVSS 4.3fixed in 78.52020-12-09
CVE-2020-26953 [MEDIUM] CWE-1021 CVE-2020-26953: It was possible to cause the browser to enter fullscreen mode without displaying the security UI; th
It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.
nvd
CVE-2021-43538P4MEDIUMCVSS 4.3fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43538 [MEDIUM] CWE-362 CVE-2021-43538: By misusing a race in our notification code, an attacker could have forcefully hidden the notificati
By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screen and pointer lock access, which could have been used for spoofing attacks. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2019-11749P4MEDIUMCVSS 4.3fixed in 68.1.0≥ unspecified, < 68.12019-09-27
CVE-2019-11749 [MEDIUM] CVE-2019-11749: A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUs
A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.
nvd
CVE-2023-5721P4MEDIUMCVSS 4.3fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5721 [MEDIUM] CWE-1021 CVE-2023-5721: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally
It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2022-22743P4MEDIUMCVSS 4.3fixed in 91.5≥ unspecified, < 91.52022-12-22
CVE-2022-22743 [MEDIUM] CVE-2022-22743: When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab
When navigating from inside an iframe while requesting fullscreen access, an attacker-controlled tab could have made the browser unable to leave fullscreen mode. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
nvd
CVE-2023-4581P4MEDIUMCVSS 4.3fixed in 102.15≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4581 [MEDIUM] CVE-2023-4581: Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which all
Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.
nvd
CVE-2024-4767P4MEDIUMCVSS 4.3≥ unspecified, < 115.112024-05-14
CVE-2024-4767 [MEDIUM] CWE-459 CVE-2024-4767: If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
nvd
CVE-2022-3266P4MEDIUMCVSS 5.5fixed in 102.3≥ unspecified, < 102.32022-12-22
CVE-2022-3266 [MEDIUM] CWE-125 CVE-2022-3266: An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.
nvd
CVE-2012-0451P4MEDIUMCVSS 4.3v10.1v10.22012-03-14
CVE-2012-0451 [MEDIUM] CWE-94 CVE-2012-0451: CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Th
CRLF injection vulnerability in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote web servers to bypass intended Content Security Policy (CSP) restrictions and possibly conduct cross-site scripting (XSS) attacks via crafted HTTP head
nvd
CVE-2018-12367P4MEDIUMCVSS 4.3≥ unspecified, < 60.12018-10-18
CVE-2018-12367 [MEDIUM] CWE-20 CVE-2018-12367: In the previous mitigations for Spectre, the resolution or precision of various methods was reduced
In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Fire
nvd
CVE-2021-43546P4MEDIUMCVSS 4.3fixed in 91.4.0≥ unspecified, < 91.4.02021-12-08
CVE-2021-43546 [MEDIUM] CWE-1021 CVE-2021-43546: It was possible to recreate previous cursor spoofing attacks against users with a zoomed native curs
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
nvd
CVE-2015-2741P4MEDIUMCVSS 4.3v31.1v31.2+5 more2015-07-06
CVE-2015-2741 [MEDIUM] CWE-310 CVE-2015-2741: Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforc
Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname f
nvd
CVE-2021-23969P4MEDIUMCVSS 4.3fixed in 78.82021-02-26
CVE-2021-23969 [MEDIUM] CVE-2021-23969: As specified in the W3C Content Security Policy draft, when creating a violation report, "User agent
As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the s
nvd
CVE-2015-0833P4MEDIUMCVSS 6.9v31.1v31.2+3 more2015-02-25
CVE-2015-0833 [MEDIUM] CVE-2015-0833: Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefo
Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dl
nvd
CVE-2022-26383P4MEDIUMCVSS 4.3fixed in 91.7≥ unspecified, < 91.72022-12-22
CVE-2022-26383 [MEDIUM] CWE-451 CVE-2022-26383: When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen
When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.
nvd