cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 6 of 49
CVE-2026-84134P3UNKNOWNfixed in Firefox ESR 153.2
CVE-2026-84134 Mozilla Foundation Security Advisory 2026-85: CVE-2026-84134 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84134 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2018-5127P3HIGHCVSS 8.8≥ unspecified, < 52.72018-06-11
CVE-2018-5127 [HIGH] CWE-119 CVE-2018-5127: A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This res A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.7, Firefox ESR < 52.7, and Firefox < 59.
nvd
CVE-2021-24002P3HIGHCVSS 8.8fixed in 78.10≥ unspecified, < 78.102021-06-24
CVE-2021-24002 [HIGH] CWE-74 CVE-2021-24002: When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and allowed arbitrary commands to be sent to the FTP server. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
nvd
CVE-2022-22756P3HIGHCVSS 8.8fixed in 91.6≥ unspecified, < 91.62022-12-22
CVE-2022-22756 [HIGH] CWE-94 CVE-2022-22756: If a user was convinced to drag and drop an image to their desktop or other folder, the resulting ob If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
nvd
CVE-2026-12289P3HIGHCVSS 8.8fixed in Firefox ESR 115.37
CVE-2026-12289 [HIGH] Mozilla Foundation Security Advisory 2026-59: CVE-2026-12289 Mozilla Foundation Security Advisory 2026-59 CVE: CVE-2026-12289 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.37
mozilla
CVE-2017-5390P3CRITICALCVSS 9.8≥ unspecified, < 45.72018-06-11
CVE-2017-5390 [CRITICAL] CVE-2017-5390: The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for c The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
nvd
CVE-2026-84123P3HIGHCVSS 8.8fixed in Firefox ESR 153.2
CVE-2026-84123 [HIGH] Mozilla Foundation Security Advisory 2026-85: CVE-2026-84123 Mozilla Foundation Security Advisory 2026-85 CVE: CVE-2026-84123 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.2
mozilla
CVE-2018-18492P3CRITICALCVSS 9.8≥ unspecified, < 60.42019-02-28
CVE-2018-18492 [CRITICAL] CWE-416 CVE-2018-18492: A use-after-free vulnerability can occur after deleting a selection element due to a weak reference A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2016-9901P3CRITICALCVSS 9.8≥ unspecified, < 45.62018-06-11
CVE-2016-9901 [CRITICAL] CWE-20 CVE-2016-9901: HTML tags received from the Pocket server will be processed without sanitization and any JavaScript HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
nvd
CVE-2024-2607P3HIGHCVSS 8.1≥ unspecified, < 115.92024-03-19
CVE-2024-2607 [HIGH] CWE-123 CVE-2024-2607: Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *N Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2017-7828P3CRITICALCVSS 9.8≥ unspecified, < 52.52018-06-11
CVE-2017-7828 [CRITICAL] CWE-416 CVE-2017-7828: A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in use. This results in a potentially exploitable crash during these operations. This vulnerability affects Firefox < 57, Firefox ESR < 52.5, and Thunderbird < 52.5.
nvd
CVE-2023-5174P3CRITICALCVSS 9.8fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5174 [CRITICAL] CWE-416 CVE-2023-5174: If Windows failed to duplicate a handle during process creation, the sandbox code may have inadverte If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vul
nvd
CVE-2024-9394P3HIGHCVSS 7.5fixed in 115.16.0≥ 116.0, < 128.3.0+2 more2024-10-01
CVE-2024-9394 [HIGH] CWE-79 CVE-2024-9394: An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under th An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This
nvd
CVE-2024-9401P3CRITICALCVSS 9.8≥ unspecified, < 128.3≥ unspecified, < 115.162024-10-01
CVE-2024-9401 [CRITICAL] CWE-119 CVE-2024-9401: Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 12 Memory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thu
nvd
CVE-2026-74990P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74990 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74990 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74990 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74987P3UNKNOWNfixed in Firefox ESR 140.14
CVE-2026-74987 Mozilla Foundation Security Advisory 2026-76: CVE-2026-74987 Mozilla Foundation Security Advisory 2026-76 CVE: CVE-2026-74987 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.14
mozilla
CVE-2026-8091P3UNKNOWNfixed in Firefox ESR 115.35.2
CVE-2026-8091 Mozilla Foundation Security Advisory 2026-42: CVE-2026-8091 Mozilla Foundation Security Advisory 2026-42 CVE: CVE-2026-8091 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.35.2
mozilla
CVE-2026-8094P3UNKNOWNfixed in Firefox ESR 140.10.2
CVE-2026-8094 Mozilla Foundation Security Advisory 2026-41: CVE-2026-8094 Mozilla Foundation Security Advisory 2026-41 CVE: CVE-2026-8094 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.10.2
mozilla
CVE-2026-16363P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16363 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16363 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16363 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16355P3UNKNOWNfixed in Firefox ESR 115.38
CVE-2026-16355 Mozilla Foundation Security Advisory 2026-69: CVE-2026-16355 Mozilla Foundation Security Advisory 2026-69 CVE: CVE-2026-16355 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.38
mozilla
Mozilla Firefox Esr vulnerabilities | cvebase