Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 7 of 45
CVE-2024-8382P3HIGHCVSS 8.8fixed in 115.15≥ 128.0, < 128.2+2 more2024-09-03
CVE-2024-8382 [HIGH] CWE-273 CVE-2024-8382: Internal browser event interfaces were exposed to web content when privileged EventHandler listener
Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools consol
nvd
CVE-2024-5696P3HIGHCVSS 8.6≥ unspecified, < 115.122024-06-11
CVE-2024-5696 [HIGH] CWE-787 CVE-2024-5696: By manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory lea
By manipulating the text in an ` ` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.
nvd
CVE-2026-8958P3HIGHCVSS 8.6fixed in Firefox ESR 140.11
CVE-2026-8958 [HIGH] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8958
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8958
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
mozilla
CVE-2019-11693P3CRITICALCVSS 9.8≥ unspecified, < 60.72019-07-23
CVE-2019-11693 [CRITICAL] CWE-787 CVE-2019-11693: The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers o
The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox <
nvd
CVE-2019-11692P3CRITICALCVSS 9.8≥ unspecified, < 60.72019-07-23
CVE-2019-11692 [CRITICAL] CWE-416 CVE-2019-11692: A use-after-free vulnerability can occur when listeners are removed from the event listener manager
A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2023-5730P3CRITICALCVSS 9.8fixed in 115.4≥ unspecified, < 115.42023-10-25
CVE-2023-5730 [CRITICAL] CWE-787 CVE-2023-5730: Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these b
Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
nvd
CVE-2018-5104P3CRITICALCVSS 9.8≥ unspecified, < 52.62018-06-11
CVE-2018-5104 [CRITICAL] CWE-416 CVE-2018-5104: A use-after-free vulnerability can occur during font face manipulation when a font face is freed whi
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2018-5102P3CRITICALCVSS 9.8≥ unspecified, < 52.62018-06-11
CVE-2018-5102 [CRITICAL] CWE-416 CVE-2018-5102: A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, r
A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2022-34470P3CRITICALCVSS 9.8fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-34470 [CRITICAL] CWE-416 CVE-2022-34470: Session history navigations may have led to a use-after-free and potentially exploitable crash. This
Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2022-31736P3CRITICALCVSS 9.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31736 [CRITICAL] CWE-942 CVE-2022-31736: A malicious website could have learned the size of a cross-origin resource that supported Range requ
A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2023-29531P3CRITICALCVSS 9.8fixed in 102.10≥ unspecified, < 102.102023-06-19
CVE-2023-29531 [CRITICAL] CWE-787 CVE-2023-29531: An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory cor
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash.
*This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
nvd
CVE-2023-4056P3CRITICALCVSS 9.8≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4056 [CRITICAL] CWE-787 CVE-2023-4056: Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0,
Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and
nvd
CVE-2022-46882P3CRITICALCVSS 9.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46882 [CRITICAL] CWE-416 CVE-2022-46882: A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnera
A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvd
CVE-2024-3863P3CRITICALCVSS 9.8≥ unspecified, < 115.102024-04-16
CVE-2024-3863 [CRITICAL] CWE-434 CVE-2024-3863: The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue on
The executable file warning was not presented when downloading .xrm-ms files.
*Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2024-9394P3HIGHCVSS 7.5fixed in 115.16.0≥ 116.0, < 128.3.0+2 more2024-10-01
CVE-2024-9394 [HIGH] CWE-79 CVE-2024-9394: An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under th
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This
nvd
CVE-2024-9393P3HIGHCVSS 7.5fixed in 115.16.0≥ 116.0, < 128.3.0+2 more2024-10-01
CVE-2024-9393 [HIGH] CWE-346 CVE-2024-9393: An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under th
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vu
nvd
CVE-2024-9402P3CRITICALCVSS 9.8≥ unspecified, < 128.32024-10-01
CVE-2024-9402 [CRITICAL] CWE-119 CVE-2024-9402: Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these b
Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2024-8387P3CRITICALCVSS 9.8v128.1≥ unspecified, < 128.22024-09-03
CVE-2024-8387 [CRITICAL] CWE-787 CVE-2024-8387: Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these b
Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvd
CVE-2018-12368P3HIGHCVSS 8.1fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12368 [HIGH] CVE-2018-12368: Windows 10 does not warn users before opening executable files with the SettingContent-ms extension
Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an unwanted executable. This also allows a WebExtension with the limited downloads.open per
nvd
CVE-2015-2731P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2731 [CRITICAL] CVE-2015-2731: Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation
Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allows remote attackers to execute arbitrary code by leveraging client-side JavaScript that triggers removal of a DOM object on the basis of a Content Policy.
nvd