Mozilla / Firefox Esr
715 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-9183 | Spoofing issue in the Address Bar component | MEDIUM | 6.5 | Aug 19, 2025 |
| CVE-2025-9185 | Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbi… | HIGH | 8.1 | Aug 19, 2025 |
| CVE-2025-9180 | Same-origin policy bypass in the Graphics: Canvas2D component | HIGH | 8.1 | Aug 19, 2025 |
| CVE-2024-11699 | firefox: thunderbird: Memory safety bugs fixed in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5 | HIGH | 8.8 | Nov 26, 2024 |
| CVE-2024-11698 | firefox: thunderbird: Fullscreen Lock-Up When Modal Dialog Interrupts Transition on macOS | CRITICAL | 9.8 | Nov 26, 2024 |
| CVE-2024-11704 | firefox: thunderbird: Potential Double-Free Vulnerability in PKCS#7 Decryption Handling | CRITICAL | 9.8 | Nov 26, 2024 |
| CVE-2024-11697 | firefox: thunderbird: Improper Keypress Handling in Executable File Confirmation Dialog | HIGH | 8.8 | Nov 26, 2024 |
| CVE-2024-11696 | firefox: thunderbird: Unhandled Exception in Add-on Signature Verification | MEDIUM | 5.4 | Nov 26, 2024 |
| CVE-2024-11695 | firefox: thunderbird: URL Bar Spoofing via Manipulated Punycode and Whitespace Characters | MEDIUM | 5.4 | Nov 26, 2024 |
| CVE-2024-11694 | firefox: thunderbird: CSP Bypass and XSS Exposure via Web Compatibility Shims | MEDIUM | 6.1 | Nov 26, 2024 |
| CVE-2024-11693 | firefox: thunderbird: Download Protections were bypassed by .library-ms files on Windows | CRITICAL | 9.8 | Nov 26, 2024 |
| CVE-2024-11692 | firefox: thunderbird: Select list elements could be shown over another site | MEDIUM | 5.4 | Nov 26, 2024 |
| CVE-2024-11691 | firefox: thunderbird: Memory corruption in Apple GPU drivers | HIGH | 8.8 | Nov 26, 2024 |
| CVE-2024-10467 | firefox: thunderbird: Memory safety bugs fixed in Firefox 132, Thunderbird 132, Firefox ESR 128.4, and Thunderbird 128.4 | CRITICAL | 9.8 | Oct 29, 2024 |
| CVE-2024-10466 | firefox: DOM push subscription message could hang Firefox | HIGH | 7.5 | Oct 29, 2024 |
| CVE-2024-10465 | firefox: thunderbird: Clipboard "paste" button persisted across tabs | HIGH | 7.5 | Oct 29, 2024 |
| CVE-2024-10464 | firefox: thunderbird: History interface could have been used to cause a Denial of Service condition in the browser | HIGH | 7.5 | Oct 29, 2024 |
| CVE-2024-10463 | firefox: thunderbird: Cross origin video frame leak | HIGH | 7.5 | Oct 29, 2024 |
| CVE-2024-10462 | firefox: thunderbird: Origin of permission prompt could be spoofed by long URL | HIGH | 7.5 | Oct 29, 2024 |
| CVE-2024-10461 | firefox: thunderbird: XSS due to Content-Disposition being ignored in multipart/x-mixed-replace response | MEDIUM | 6.1 | Oct 29, 2024 |
| CVE-2024-10460 | firefox: thunderbird: Confusing display of origin for external protocol handler prompt | MEDIUM | 5.4 | Oct 29, 2024 |
| CVE-2024-10459 | firefox: thunderbird: Use-after-free in layout with accessibility | HIGH | 7.6 | Oct 29, 2024 |
| CVE-2024-10458 | firefox: thunderbird: Permission leak via embed or object elements | HIGH | 8.2 | Oct 29, 2024 |
| CVE-2024-9680 KEV | firefox: Use-after-free in Animation timeline (128.3.1 ESR Chemspill) | CRITICAL | 9.8 | Oct 9, 2024 |
| CVE-2024-9402 | firefox: thunderbird: Memory safety bugs fixed in Firefox 131, Firefox ESR 128.3, Thunderbird 131, and Thunderbird 128.3 | CRITICAL | 9.8 | Oct 1, 2024 |
Showing 1 to 25 of 715 CVEs