cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 48 of 49
CVE-2023-32212P4MEDIUMCVSS 4.3fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32212 [MEDIUM] CVE-2023-32212: An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerabilit An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2023-32205P4MEDIUMCVSS 4.3fixed in 102.11≥ unspecified, < 102.112023-06-02
CVE-2023-32205 [MEDIUM] CVE-2023-32205: In multiple cases browser prompts could have been obscured by popups controlled by content. These co In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
nvd
CVE-2023-5726P4MEDIUMCVSS 4.3fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5726 [MEDIUM] CVE-2023-5726: A website could have obscured the full screen notification by using the file open dialog. This could A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. *Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2024-0742P4MEDIUMCVSS 4.3fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0742 [MEDIUM] CVE-2024-0742: It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2022-34472P4MEDIUMCVSS 4.3fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-34472 [MEDIUM] CWE-703 CVE-2022-34472: If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would If there was a PAC URL set and the server that hosts the PAC was not reachable, OCSP requests would have been blocked, resulting in incorrect error pages being shown. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2023-29533P4MEDIUMCVSS 4.3fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29533 [MEDIUM] CVE-2023-29533: A website could have obscured the fullscreen notification by using a combination of <code>window.ope A website could have obscured the fullscreen notification by using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thun
nvd
CVE-2012-0455P4MEDIUMCVSS 4.3v10.1v10.22012-03-14
CVE-2012-0455 [MEDIUM] CWE-79 CVE-2012-0455: Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird befo Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict drag-and-drop operations on javascript: URLs, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks
nvd
CVE-2020-6827P4MEDIUMCVSS 4.7fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6827 [MEDIUM] CWE-1021 CVE-2020-6827: When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firef When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
nvd
CVE-2017-5451P4MEDIUMCVSS 4.3≥ unspecified, < 52.12018-06-11
CVE-2017-5451 [MEDIUM] CWE-20 CVE-2017-5451: A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
nvd
CVE-2026-74973P4UNKNOWNfixed in Firefox ESR 115.39
CVE-2026-74973 Mozilla Foundation Security Advisory 2026-75: CVE-2026-74973 Mozilla Foundation Security Advisory 2026-75 CVE: CVE-2026-74973 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.39
mozilla
CVE-2021-23953P4MEDIUMCVSS 4.3fixed in 78.72021-02-26
CVE-2021-23953 [MEDIUM] CVE-2021-23953: If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cro If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
nvd
CVE-2020-12399P4MEDIUMCVSS 4.4fixed in 68.9.0≥ unspecified, < 68.92020-07-09
CVE-2020-12399 [MEDIUM] CWE-203 CVE-2020-12399: NSS has shown timing differences when performing DSA signatures, which was exploitable and could eve NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9.
nvd
CVE-2024-0749P4MEDIUMCVSS 4.3fixed in 115.72024-01-23
CVE-2024-0749 [MEDIUM] CWE-346 CVE-2024-0749: A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect A phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerability affects Firefox < 122 and Thunderbird < 115.7.
nvd
CVE-2026-74971P4UNKNOWNfixed in Firefox ESR 140.14
CVE-2026-74971 Mozilla Foundation Security Advisory 2026-76: CVE-2026-74971 Mozilla Foundation Security Advisory 2026-76 CVE: CVE-2026-74971 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.14
mozilla
CVE-2026-74972P4UNKNOWNfixed in Firefox ESR 140.14
CVE-2026-74972 Mozilla Foundation Security Advisory 2026-76: CVE-2026-74972 Mozilla Foundation Security Advisory 2026-76 CVE: CVE-2026-74972 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.14
mozilla
CVE-2026-84137P4UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84137 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84137 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84137 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2021-23968P4MEDIUMCVSS 4.3fixed in 78.82021-02-26
CVE-2021-23968 [MEDIUM] CWE-209 CVE-2021-23968: If Content Security Policy blocked frame navigation, the full destination of a redirect served in th If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.
nvd
CVE-2024-3861P4MEDIUMCVSS 4.0≥ unspecified, < 115.102024-04-16
CVE-2024-3861 [MEDIUM] CWE-416 CVE-2024-3861: If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect r If an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2019-11743P4LOWCVSS 3.7≥ 68.0, < 68.1.0≥ unspecified, < 60.9+1 more2019-09-27
CVE-2019-11743 [LOW] CWE-203 CVE-2019-11743: Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specificati Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affect
nvd
CVE-2024-3302P4LOWCVSS 3.7≥ unspecified, < 115.102024-04-16
CVE-2024-3302 [LOW] CWE-770 CVE-2024-3302: There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server cou There was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of Memory condition in the browser. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase