cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 7 of 49
CVE-2026-16368P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16368 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16368 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16368 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-74959P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74959 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74959 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74959 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74938P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74938 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74938 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74938 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2020-6831P3CRITICALCVSS 9.8fixed in 68.8.0≥ unspecified, < 68.82020-05-26
CVE-2020-6831 [CRITICAL] CWE-787 CVE-2020-6831: A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
nvd
CVE-2026-16358P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16358 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16358 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16358 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16375P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16375 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16375 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16375 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-16387P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16387 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16387 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16387 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2017-7778P3CRITICALCVSS 9.8≥ unspecified, < 52.22018-06-11
CVE-2017-7778 [CRITICAL] CWE-119 CVE-2017-7778: A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
nvd
CVE-2014-1568P3HIGHCVSS 7.5v24.8.02014-09-25
CVE-2014-1568 [HIGH] CWE-310 CVE-2014-1568: Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.1 Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X
nvd
CVE-2026-8950P3CRITICALCVSS 9.3fixed in Firefox ESR 140.11
CVE-2026-8950 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8950 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8950 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2023-0767P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-0767 [HIGH] CVE-2023-0767: An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memor An attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributes being mishandled. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.
nvd
CVE-2023-6207P3HIGHCVSS 8.8fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6207 [HIGH] CWE-416 CVE-2023-6207: Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Fi Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2024-7520P3HIGHCVSS 8.8fixed in 128.1.0≥ unspecified, < 128.12024-08-06
CVE-2024-7520 [HIGH] CWE-843 CVE-2024-7520: A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code ex A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
nvd
CVE-2026-8957P3MEDIUMCVSS 6.5fixed in Firefox ESR 140.11
CVE-2026-8957 [MEDIUM] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8957 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8957 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2024-8382P3HIGHCVSS 8.8fixed in 115.15≥ 128.0, < 128.2+2 more2024-09-03
CVE-2024-8382 [HIGH] CWE-273 CVE-2024-8382: Internal browser event interfaces were exposed to web content when privileged EventHandler listener Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools consol
nvd
CVE-2016-9900P3HIGHCVSS 7.5≥ unspecified, < 45.62018-06-11
CVE-2016-9900 [HIGH] CWE-254 CVE-2016-9900: External resources that should be blocked when loaded by SVG images can bypass security restrictions External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
nvd
CVE-2026-84131P3HIGHCVSS 8.8fixed in Firefox ESR 115.40
CVE-2026-84131 [HIGH] Mozilla Foundation Security Advisory 2026-83: CVE-2026-84131 Mozilla Foundation Security Advisory 2026-83 CVE: CVE-2026-84131 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.40
mozilla
CVE-2026-8958P3HIGHCVSS 8.6fixed in Firefox ESR 140.11
CVE-2026-8958 [HIGH] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8958 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8958 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2024-5688P3HIGHCVSS 8.1≥ unspecified, < 115.122024-06-11
CVE-2024-5688 [HIGH] CWE-416 CVE-2024-5688: If a garbage collection was triggered at the right time, a use-after-free could have occurred during If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2019-11693P3CRITICALCVSS 9.8≥ unspecified, < 60.72019-07-23
CVE-2019-11693 [CRITICAL] CWE-787 CVE-2019-11693: The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers o The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox <
nvd
Mozilla Firefox Esr vulnerabilities | cvebase