cbcvebase.

Mozilla Firefox Esr vulnerabilities

963 known vulnerabilities affecting mozilla/firefox_esr.

Total CVEs
963
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL202HIGH350MEDIUM297LOW6UNKNOWN108

Vulnerabilities

Page 9 of 49
CVE-2026-74956P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74956 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74956 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74956 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-74961P3UNKNOWNfixed in Firefox ESR 153.1
CVE-2026-74961 Mozilla Foundation Security Advisory 2026-77: CVE-2026-74961 Mozilla Foundation Security Advisory 2026-77 CVE: CVE-2026-74961 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 153.1
mozilla
CVE-2026-16381P3UNKNOWNfixed in Firefox ESR 140.13
CVE-2026-16381 Mozilla Foundation Security Advisory 2026-70: CVE-2026-16381 Mozilla Foundation Security Advisory 2026-70 CVE: CVE-2026-16381 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.13
mozilla
CVE-2019-11759P3HIGHCVSS 8.8fixed in 68.2vbefore 68.22020-01-08
CVE-2019-11759 [HIGH] CWE-120 CVE-2019-11759: An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored o An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.
nvd
CVE-2014-1551P3CRITICALCVSS 10.0v24.2v24.3+3 more2014-07-23
CVE-2014-1551 [CRITICAL] CVE-2014-1551: Use-after-free vulnerability in the FontTableRec destructor in Mozilla Firefox before 31.0, Firefox Use-after-free vulnerability in the FontTableRec destructor in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 on Windows allows remote attackers to execute arbitrary code via crafted use of fonts in MathML content, leading to improper handling of a DirectWrite font-face object.
nvd
CVE-2017-5448P3HIGHCVSS 8.6≥ unspecified, < 45.9≥ unspecified, < 52.12018-06-11
CVE-2017-5448 [HIGH] CWE-787 CVE-2017-5448: An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash.
nvd
CVE-2020-6822P3HIGHCVSS 8.8fixed in 68.7.0≥ unspecified, < 68.72020-04-24
CVE-2020-6822 [HIGH] CWE-787 CVE-2020-6822: On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.7.0, Firefox ESR < 68.7, and Firefox < 75.
nvd
CVE-2023-4582P3HIGHCVSS 8.8fixed in 115.2≥ unspecified, < 115.22023-09-11
CVE-2023-4582 [HIGH] CWE-120 CVE-2023-4582: Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could h Due to large allocation checks in Angle for glsl shaders being too lenient a buffer overflow could have occurred when allocating too much private shader memory on mac OS. *This bug only affects Firefox on macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
nvd
CVE-2024-0750P3HIGHCVSS 8.8fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0750 [HIGH] CWE-451 CVE-2024-0750: A bug in popup notifications delay calculation could have made it possible for an attacker to trick A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2023-4584P3HIGHCVSS 8.8fixed in 102.15≥ unspecified, < 102.15+1 more2023-09-11
CVE-2023-4584 [HIGH] CWE-787 CVE-2023-4584: Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14 Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox
nvd
CVE-2023-6208P3HIGHCVSS 8.8fixed in 115.5.0≥ unspecified, < 115.5.02023-11-21
CVE-2023-6208 [HIGH] CVE-2023-6208: When using X11, text selected by the page using the Selection API was erroneously copied into the pr When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
nvd
CVE-2023-29541P3HIGHCVSS 8.8fixed in 102.10≥ unspecified, < 102.102023-06-02
CVE-2023-29541 [HIGH] CWE-116 CVE-2023-29541: Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be int Firefox did not properly handle downloads of files ending in .desktop, which can be interpreted to run attacker-controlled commands. *This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112,
nvd
CVE-2024-11691P3HIGHCVSS 8.8≥ unspecified, < 128.5≥ unspecified, < 115.182024-11-26
CVE-2024-11691 [HIGH] CWE-787 CVE-2024-11691: Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write Certain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in Apple's GPU driver. *This bug only affected the application on Apple M series hardware. Other platforms were unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunde
nvd
CVE-2024-11699P3HIGHCVSS 8.8≥ unspecified, < 128.52024-11-26
CVE-2024-11699 [HIGH] CWE-94 CVE-2024-11699: Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these b Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
nvd
CVE-2026-8955P3MEDIUMCVSS 6.5fixed in Firefox ESR 140.11
CVE-2026-8955 [MEDIUM] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8955 Mozilla Foundation Security Advisory 2026-48 CVE: CVE-2026-8955 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 140.11
mozilla
CVE-2024-0751P3HIGHCVSS 8.8fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0751 [HIGH] CWE-269 CVE-2024-0751: A malicious devtools extension could have been used to escalate privileges. This vulnerability affec A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2024-7521P3HIGHCVSS 8.8fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7521 [HIGH] CWE-755 CVE-2024-7521: Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affe Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2024-7527P3HIGHCVSS 8.8fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7527 [HIGH] CWE-416 CVE-2024-7527: Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerabil Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2024-10467P3HIGHCVSS 8.8≥ unspecified, < 128.42024-10-29
CVE-2024-10467 [HIGH] CWE-787 CVE-2024-10467: Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these b Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-6750P3HIGHCVSS 8.8fixed in Firefox ESR 115.35
CVE-2026-6750 [HIGH] Mozilla Foundation Security Advisory 2026-31: CVE-2026-6750 Mozilla Foundation Security Advisory 2026-31 CVE: CVE-2026-6750 Product: Firefox ESR Impact: high Fixed in: Firefox ESR 115.35
mozilla
Mozilla Firefox Esr vulnerabilities | cvebase