Mozilla Firefox Esr vulnerabilities
963 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108
Vulnerabilities
Page 5 of 49
CVE-2026-16390P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16390 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16390
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-16390
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
mozilla
CVE-2024-2614P3HIGHCVSS 8.8≥ unspecified, < 115.92024-03-19
CVE-2024-2614 [HIGH] CWE-787 CVE-2024-2614: Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these b
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2024-3854P3HIGHCVSS 8.8≥ unspecified, < 115.102024-04-16
CVE-2024-3854 [HIGH] CWE-125 CVE-2024-3854: In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of
In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2018-18498P3CRITICALCVSS 9.8fixed in 60.4≥ unspecified, < 60.42019-02-28
CVE-2018-18498 [CRITICAL] CWE-190 CVE-2018-18498: A potential vulnerability leading to an integer overflow can occur during buffer size calculations f
A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used instead of the checked value. This leads to a possible out-of-bounds write. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2022-46872P3HIGHCVSS 8.6fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46872 [HIGH] CWE-125 CVE-2022-46872: An attacker who compromised a content process could have partially escaped the sandbox to read arbit
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvd
CVE-2014-1557P3CRITICALCVSS 9.3v24.2v24.3+3 more2014-07-23
CVE-2014-1557 [CRITICAL] CWE-94 CVE-2014-1557: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x
The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a hig
nvd
CVE-2018-5158P3HIGHCVSS 8.8≥ unspecified, < 52.82018-06-11
CVE-2018-5158 [HIGH] CWE-94 CVE-2018-5158: The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious Ja
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
nvd
CVE-2018-12387P3CRITICALCVSS 9.1≥ unspecified, < 60.2.22018-10-18
CVE-2018-12387 [CRITICAL] CWE-20 CVE-2018-12387: A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple argumen
A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2
nvd
CVE-2024-11693P3CRITICALCVSS 9.8≥ unspecified, < 128.52024-11-26
CVE-2024-11693 [CRITICAL] CVE-2024-11693: The executable file warning was not presented when downloading .library-ms files. *Note: This issu
The executable file warning was not presented when downloading .library-ms files.
*Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2024-11698P3CRITICALCVSS 9.8≥ unspecified, < 128.52024-11-26
CVE-2024-11698 [CRITICAL] CVE-2024-11698: A flaw in handling fullscreen transitions may have inadvertently caused the application to become st
A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until t
nvd
CVE-2026-8975P3CRITICALCVSS 9.8fixed in Firefox ESR 140.11
CVE-2026-8975 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8975
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8975
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-2781P3CRITICALCVSS 9.8fixed in Firefox ESR 115.35
CVE-2026-2781 [CRITICAL] Mozilla Foundation Security Advisory 2026-31: CVE-2026-2781
Mozilla Foundation Security Advisory 2026-31
CVE: CVE-2026-2781
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35
mozilla
CVE-2026-16353P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16353 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16353
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-16353
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-74940P3UNKNOWNfixed in Firefox ESR 115.39
CVE-2026-74940 Mozilla Foundation Security Advisory 2026-75: CVE-2026-74940
Mozilla Foundation Security Advisory 2026-75
CVE: CVE-2026-74940
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.39
mozilla
CVE-2026-16357P3UNKNOWNfixed in Firefox ESR 115.38
CVE-2026-16357 Mozilla Foundation Security Advisory 2026-69: CVE-2026-16357
Mozilla Foundation Security Advisory 2026-69
CVE: CVE-2026-16357
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.38
mozilla
CVE-2026-74944P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74944 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74944
Mozilla Foundation Security Advisory 2026-77
CVE: CVE-2026-74944
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74936P3UNKNOWNfixed in Firefox ESR 140.14
CVE-2026-74936 Mozilla Foundation Security Advisory 2026-76: CVE-2026-74936
Mozilla Foundation Security Advisory 2026-76
CVE: CVE-2026-74936
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.14
mozilla
CVE-2026-16377P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16377 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16377
Mozilla Foundation Security Advisory 2026-70
CVE: CVE-2026-16377
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-84143P3UNKNOWNfixed in Firefox ESR 140.15
CVE-2026-84143 Mozilla Foundation Security Advisory 2026-84: CVE-2026-84143
Mozilla Foundation Security Advisory 2026-84
CVE: CVE-2026-84143
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.15
mozilla
CVE-2026-84119P3CRITICALCVSS 9.6fixed in Firefox ESR 153.2
CVE-2026-84119 [CRITICAL] Mozilla Foundation Security Advisory 2026-85: CVE-2026-84119
Mozilla Foundation Security Advisory 2026-85
CVE: CVE-2026-84119
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 153.2
mozilla