cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 5 of 45
CVE-2026-8974P3CRITICALCVSS 9.8fixed in Firefox ESR 140.11
CVE-2026-8974 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8974 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8974 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-16353P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16353 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16353 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16353 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16358P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16358 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16358 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16358 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2024-3854P3HIGHCVSS 8.8≥ unspecified, < 115.102024-04-16
CVE-2024-3854 [HIGH] CWE-125 CVE-2024-3854: In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of In some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2022-46872P3HIGHCVSS 8.6fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46872 [HIGH] CWE-125 CVE-2022-46872: An attacker who compromised a content process could have partially escaped the sandbox to read arbit An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvd
CVE-2014-1557P3CRITICALCVSS 9.3v24.2v24.3+3 more2014-07-23
CVE-2014-1557 [CRITICAL] CWE-94 CVE-2014-1557: The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x The ConvolveHorizontally function in Skia, as used in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, does not properly handle the discarding of image data during function execution, which allows remote attackers to execute arbitrary code by triggering prolonged image scaling, as demonstrated by scaling of a hig
nvd
CVE-2018-18492P3CRITICALCVSS 9.8≥ unspecified, < 60.42019-02-28
CVE-2018-18492 [CRITICAL] CWE-416 CVE-2018-18492: A use-after-free vulnerability can occur after deleting a selection element due to a weak reference A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2018-12387P3CRITICALCVSS 9.1≥ unspecified, < 60.2.22018-10-18
CVE-2018-12387 [CRITICAL] CWE-20 CVE-2018-12387: A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple argumen A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process. This vulnerability affects Firefox ESR < 60.2
nvd
CVE-2024-11693P3CRITICALCVSS 9.8≥ unspecified, < 128.52024-11-26
CVE-2024-11693 [CRITICAL] CVE-2024-11693: The executable file warning was not presented when downloading .library-ms files. *Note: This issu The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2024-11698P3CRITICALCVSS 9.8≥ unspecified, < 128.52024-11-26
CVE-2024-11698 [CRITICAL] CVE-2024-11698: A flaw in handling fullscreen transitions may have inadvertently caused the application to become st A flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialog was opened during the transition. This issue left users unable to exit fullscreen mode using standard actions like pressing "Esc" or accessing right-click menus, resulting in a disrupted browsing experience until t
nvd
CVE-2026-8975P3CRITICALCVSS 9.8fixed in Firefox ESR 140.11
CVE-2026-8975 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8975 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8975 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-2781P3CRITICALCVSS 9.8fixed in Firefox ESR 115.35
CVE-2026-2781 [CRITICAL] Mozilla Foundation Security Advisory 2026-31: CVE-2026-2781 Mozilla Foundation Security Advisory 2026-31 CVE: CVE-2026-2781 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.35
mozilla
CVE-2026-8094P3UNKNOWNfixed in Firefox ESR 140.10.2
CVE-2026-8094 Mozilla Foundation Security Advisory 2026-41: CVE-2026-8094 Mozilla Foundation Security Advisory 2026-41 CVE: CVE-2026-8094 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10.2
mozilla
CVE-2026-16375P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16375 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16375 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16375 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16381P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16381 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16381 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16381 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2021-24002P3HIGHCVSS 8.8fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-24002 [HIGH] CWE-74 CVE-2021-24002: When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2022-22756P3HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22756 [HIGH] CWE-94 CVE-2022-22756: If a user was convinced to drag and drop an image to their desktop or other folder, the resulting ob If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2017-5390P3CRITICALCVSS 9.8≥ unspecified, < 45.72018-06-11
CVE-2017-5390 [CRITICAL] CVE-2017-5390: The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for c The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2026-12289P3HIGHCVSS 8.8fixed in Firefox ESR 115.37
CVE-2026-12289 [HIGH] Mozilla Foundation Security Advisory 2026-59: CVE-2026-12289 Mozilla Foundation Security Advisory 2026-59 CVE: CVE-2026-12289 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.37
mozilla
CVE-2016-9901P3CRITICALCVSS 9.8≥ unspecified, < 45.62018-06-11
CVE-2016-9901 [CRITICAL] CWE-20 CVE-2016-9901: HTML tags received from the Pocket server will be processed without sanitization and any JavaScript HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase