cbcvebase.

Mozilla Firefox Esr vulnerabilities

886 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45

Vulnerabilities

Page 8 of 45
CVE-2026-8970P3HIGHCVSS 7.3fixed in Firefox ESR 140.11
CVE-2026-8970 [HIGH] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8970 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8970 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2026-16369P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16369 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16369 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16369 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2026-8959P3CRITICALCVSS 9.6fixed in Firefox ESR 140.11
CVE-2026-8959 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8959 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8959 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2019-11759P3HIGHCVSS 8.8fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11759 [HIGH] CWE-120 CVE-2019-11759: An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored o An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2017-5448P3HIGHCVSS 8.6≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5448 [HIGH] CWE-787 CVE-2017-5448: An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash.
nvd
CVE-2018-18493P3CRITICALCVSS 9.8≥ unspecified, < 60.42019-02-28
CVE-2018-18493 [CRITICAL] CWE-119 CVE-2018-18493: A buffer overflow can occur in the Skia library during buffer offset calculations with hardware acce A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.
nvd
CVE-2023-6861P3HIGHCVSS 8.8fixed in 115.6≥ unspecified, < 115.62023-12-19
CVE-2023-6861 [HIGH] CWE-787 CVE-2023-6861: The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in he The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
nvd
CVE-2020-6822P3HIGHCVSS 8.8fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6822 [HIGH] CWE-787 CVE-2020-6822: On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvd
CVE-2020-15669P3HIGHCVSS 8.8fixed in 68.12≥ unspecified, < 68.122020-10-01
CVE-2020-15669 [HIGH] CWE-416 CVE-2020-15669: When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objec When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.12 and Thunderbird < 68.12.
nvd
CVE-2024-0750P3HIGHCVSS 8.8fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0750 [HIGH] CWE-451 CVE-2024-0750: A bug in popup notifications delay calculation could have made it possible for an attacker to trick A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2014-1568P3HIGHCVSS 7.5v24.8.02014-09-25
CVE-2014-1568 [HIGH] CWE-310 CVE-2014-1568: Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.1 Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mozilla Firefox ESR 24.x before 24.8.1 and 31.x before 31.1.1, Mozilla Thunderbird before 24.8.1 and 31.x before 31.1.2, Mozilla SeaMonkey before 2.29.1, Google Chrome before 37.0.2062.124 on Windows and OS X
nvd
CVE-2023-4584P3HIGHCVSS 8.8fixed in 102.15≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4584 [HIGH] CWE-787 CVE-2023-4584: Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14 Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox
nvd
CVE-2023-6207P3HIGHCVSS 8.8fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6207 [HIGH] CWE-416 CVE-2023-6207: Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Fi Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2023-6208P3HIGHCVSS 8.8fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6208 [HIGH] CVE-2023-6208: When using X11, text selected by the page using the Selection API was erroneously copied into the pr When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2023-4582P3HIGHCVSS 8.8fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4582 [HIGH] CWE-120 CVE-2023-4582: Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could h Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2024-11691P3HIGHCVSS 8.8≥ unspecified, < 128.5≥ unspecified, < 115.182024-11-26
CVE-2024-11691 [HIGH] CWE-787 CVE-2024-11691: Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunde
nvd
CVE-2024-11699P3HIGHCVSS 8.8≥ unspecified, < 128.52024-11-26
CVE-2024-11699 [HIGH] CWE-94 CVE-2024-11699: Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these b Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2023-25729P3HIGHCVSS 8.8fixed in 102.8≥ unspecified, < 102.82023-06-02
CVE-2023-25729 [HIGH] CWE-863 CVE-2023-25729: Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> r Permission prompts for opening external schemes were only shown for ContentPrincipals resulting in extensions being able to open them without user interaction via ExpandedPrincipals. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox <
nvd
CVE-2026-8955P3MEDIUMCVSS 6.5fixed in Firefox ESR 140.11
CVE-2026-8955 [MEDIUM] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8955 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8955 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2023-3600P3HIGHCVSS 8.8fixed in 115.0.2≥ unspecified, < 115.0.22023-07-12
CVE-2023-3600 [HIGH] CWE-416 CVE-2023-3600: During the worker lifecycle, a use-after-free condition could have occurred, which could have led to During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.
nvd
Mozilla Firefox Esr vulnerabilities | cvebase