cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 8 of 49
CVE-2019-11692P3CRITICALCVSS 9.8≥ unspecified, < 60.72019-07-23
CVE-2019-11692 [CRITICAL] CWE-416 CVE-2019-11692: A use-after-free vulnerability can occur when listeners are removed from the event listener manager A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
nvd
CVE-2018-5097P3CRITICALCVSS 9.8≥ unspecified, < 52.62018-06-11
CVE-2018-5097 [CRITICAL] CWE-416 CVE-2018-5097: A use-after-free vulnerability can occur during XSL transformations when the source document for the A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by script content during the transformation. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2018-5102P3CRITICALCVSS 9.8≥ unspecified, < 52.62018-06-11
CVE-2018-5102 [CRITICAL] CWE-416 CVE-2018-5102: A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, r A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
nvd
CVE-2022-34470P3CRITICALCVSS 9.8fixed in 91.11≥ unspecified, < 91.112022-12-22
CVE-2022-34470 [CRITICAL] CWE-416 CVE-2022-34470: Session history navigations may have led to a use-after-free and potentially exploitable crash. This Session history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.
nvd
CVE-2022-31736P3CRITICALCVSS 9.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31736 [CRITICAL] CWE-942 CVE-2022-31736: A malicious website could have learned the size of a cross-origin resource that supported Range requ A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2024-6602P3CRITICALCVSS 9.8≥ unspecified, < 115.132024-07-09
CVE-2024-6602 [CRITICAL] CWE-94 CVE-2024-6602: A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
nvd
CVE-2023-29531P3CRITICALCVSS 9.8fixed in 102.10≥ unspecified, < 102.102023-06-19
CVE-2023-29531 [CRITICAL] CWE-787 CVE-2023-29531: An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory cor An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.
nvd
CVE-2023-34416P3CRITICALCVSS 9.8fixed in 102.12≥ unspecified, < 102.122023-06-19
CVE-2023-34416 [CRITICAL] CWE-787 CVE-2023-34416: Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.
nvd
CVE-2022-46882P3CRITICALCVSS 9.8fixed in 102.6≥ unspecified, < 102.62022-12-22
CVE-2022-46882 [CRITICAL] CWE-416 CVE-2022-46882: A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnera A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.
nvd
CVE-2024-3863P3CRITICALCVSS 9.8≥ unspecified, < 115.102024-04-16
CVE-2024-3863 [CRITICAL] CWE-434 CVE-2024-3863: The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue on The executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2024-8384P3CRITICALCVSS 9.8fixed in 115.15≥ 128.0, < 128.2+2 more2024-09-03
CVE-2024-8384 [CRITICAL] CWE-787 CVE-2024-8384: The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were de The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.
nvd
CVE-2024-9393P3HIGHCVSS 7.5fixed in 115.16.0≥ 116.0, < 128.3.0+2 more2024-10-01
CVE-2024-9393 [HIGH] CWE-346 CVE-2024-9393: An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under th An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vu
nvd
CVE-2024-9402P3CRITICALCVSS 9.8≥ unspecified, < 128.32024-10-01
CVE-2024-9402 [CRITICAL] CWE-119 CVE-2024-9402: Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these b Memory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.
nvd
CVE-2024-8387P3CRITICALCVSS 9.8v128.1≥ unspecified, < 128.22024-09-03
CVE-2024-8387 [CRITICAL] CWE-787 CVE-2024-8387: Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these b Memory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.
nvd
CVE-2018-12368P3HIGHCVSS 8.1fixed in 52.9≥ unspecified, < 60.1+1 more2018-10-18
CVE-2018-12368 [HIGH] CVE-2018-12368: Windows 10 does not warn users before opening executable files with the SettingContent-ms extension Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an unwanted executable. This also allows a WebExtension with the limited downloads.open per
nvd
CVE-2015-2731P3CRITICALCVSS 10.0v31.1v31.2+5 more2015-07-06
CVE-2015-2731 [CRITICAL] CVE-2015-2731: Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation Use-after-free vulnerability in the CSPService::ShouldLoad function in the microtask implementation in Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 allows remote attackers to execute arbitrary code by leveraging client-side JavaScript that triggers removal of a DOM object on the basis of a Content Policy.
nvd
CVE-2026-8970P3HIGHCVSS 7.3fixed in Firefox ESR 140.11
CVE-2026-8970 [HIGH] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8970 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8970 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-8959P3CRITICALCVSS 9.6fixed in Firefox ESR 140.11
CVE-2026-8959 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8959 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8959 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-74988P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74988 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74988 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74988 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74986P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74986 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74986 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74986 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
Mozilla Firefox Esr vulnerabilities | cvebase