Mozilla Firefox Esr vulnerabilities
886 known vulnerabilities affecting mozilla/firefox_esr.
Total CVEs
886
CISA KEV
9
actively exploited
Public exploits
20
Exploited in wild
16
Severity breakdown
CRITICAL199HIGH344MEDIUM292LOW6UNKNOWN45
Vulnerabilities
Page 9 of 45
CVE-2024-0751P3HIGHCVSS 8.8fixed in 115.7≥ unspecified, < 115.72024-01-23
CVE-2024-0751 [HIGH] CWE-269 CVE-2024-0751: A malicious devtools extension could have been used to escalate privileges. This vulnerability affec
A malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.
nvd
CVE-2024-7521P3HIGHCVSS 8.8fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7521 [HIGH] CWE-755 CVE-2024-7521: Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affe
Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2024-7527P3HIGHCVSS 8.8fixed in 115.14.0v128.0+2 more2024-08-06
CVE-2024-7527 [HIGH] CWE-416 CVE-2024-7527: Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerabil
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
nvd
CVE-2024-10467P3HIGHCVSS 8.8≥ unspecified, < 128.42024-10-29
CVE-2024-10467 [HIGH] CWE-787 CVE-2024-10467: Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these b
Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.
nvd
CVE-2026-6750P3HIGHCVSS 8.8fixed in Firefox ESR 115.35
CVE-2026-6750 [HIGH] Mozilla Foundation Security Advisory 2026-31: CVE-2026-6750
Mozilla Foundation Security Advisory 2026-31
CVE: CVE-2026-6750
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.35
mozilla
CVE-2026-6769P3HIGHCVSS 8.8fixed in Firefox ESR 140.10
CVE-2026-6769 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6769
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6769
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2026-6761P3HIGHCVSS 8.8fixed in Firefox ESR 140.10
CVE-2026-6761 [HIGH] Mozilla Foundation Security Advisory 2026-32: CVE-2026-6761
Mozilla Foundation Security Advisory 2026-32
CVE: CVE-2026-6761
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.10
mozilla
CVE-2014-1555P3CRITICALCVSS 9.3v24.2v24.3+3 more2014-07-23
CVE-2014-1555 [CRITICAL] CVE-2014-1555: Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0,
Use-after-free vulnerability in the nsDocLoader::OnProgress function in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allows remote attackers to execute arbitrary code via vectors that trigger a FireOnStateChange event.
nvd
CVE-2018-12392P3CRITICALCVSS 9.8≥ unspecified, < 60.32019-02-28
CVE-2018-12392 [CRITICAL] CVE-2018-12392: When manipulating user events in nested loops while opening a document through script, it is possibl
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
nvd
CVE-2017-5428P3CRITICALCVSS 9.8fixed in 52.0.1≥ unspecified, < 52.0.12018-06-11
CVE-2017-5428 [CRITICAL] CWE-190 CVE-2017-5428: An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for t
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Fir
nvd
CVE-2024-2612P3HIGHCVSS 8.1≥ unspecified, < 115.92024-03-19
CVE-2024-2612 [HIGH] CWE-416 CVE-2024-2612: If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have tri
If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
nvd
CVE-2024-3864P3HIGHCVSS 8.1≥ unspecified, < 115.102024-04-16
CVE-2024-3864 [HIGH] CWE-119 CVE-2024-3864: Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed
Memory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.
nvd
CVE-2018-12369P3CRITICALCVSS 9.8≥ unspecified, < 60.12018-10-18
CVE-2018-12369 [CRITICAL] CWE-863 CVE-2018-12369: WebExtensions bundled with embedded experiments were not correctly checked for proper authorization.
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.
nvd
CVE-2023-4050P3HIGHCVSS 7.5≥ unspecified, < 102.14≥ unspecified, < 115.12023-08-01
CVE-2023-4050 [HIGH] CWE-787 CVE-2023-4050: In some cases, an untrusted input stream was copied to a stack buffer without checking its size. Thi
In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
nvd
CVE-2023-5176P3CRITICALCVSS 9.8fixed in 115.3≥ unspecified, < 115.32023-09-27
CVE-2023-5176 [CRITICAL] CWE-787 CVE-2023-5176: Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these b
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2022-31737P3CRITICALCVSS 9.8fixed in 91.10≥ unspecified, < 91.102022-12-22
CVE-2022-31737 [CRITICAL] CWE-787 CVE-2022-31737: A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption
A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.
nvd
CVE-2026-12327P3HIGHCVSS 7.3fixed in Firefox ESR 140.12
CVE-2026-12327 [HIGH] Mozilla Foundation Security Advisory 2026-58: CVE-2026-12327
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12327
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla
CVE-2019-11730P3MEDIUMCVSS 6.5fixed in 60.8≥ unspecified, < 60.82019-07-23
CVE-2019-11730 [MEDIUM] CVE-2019-11730: A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs
A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in comb
nvd
CVE-2019-17017P3HIGHCVSS 8.8fixed in 68.42020-01-08
CVE-2019-17017 [HIGH] CWE-843 CVE-2019-17017: Due to a missing case handling object types, a type confusion vulnerability could occur, resulting i
Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
nvd
CVE-2026-12296P3UNKNOWNfixed in Firefox ESR 140.12
CVE-2026-12296 Mozilla Foundation Security Advisory 2026-58: CVE-2026-12296
Mozilla Foundation Security Advisory 2026-58
CVE: CVE-2026-12296
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.12
mozilla