Known vulnerabilities in Firefox ESR
Vendor:
Mozilla
Software:
Firefox ESR
Software CPE:
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
Website:
https://www.mozilla.org
Total vulnerabilities:
998
Public exploits:
30
Known exploited (KEV):
13
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
153.0
140.13.0
115.38.0
140.12.0
115.37.0
140.11.0
115.36.0
140.10.2
115.35.2
140.10.1
115.35.1
140.10.0
115.35.0
140.9.1
115.34.1
140.9.0
115.34.0
140.8.0
115.33.0
140.7.1
115.32.1
140.7.0
115.32.0
140.6.0
115.31.0
140.5.0
115.30.0
140.4.0
115.29.0
140.3.1
140.3.0
115.28.0
140.2.0
128.14.0
115.27.0
140.1.0
128.13.0
115.26.0
140.0
128.12.0
115.25.0
128.11.0
115.24.0
128.10.1
115.23.1
128.10.0
115.23.0
128.9.0
115.22.0
115.21.1
128.8.1
128.8.0
115.21.0
128.7.0
115.20.0
128.6.0
115.19.0
128.5.2
128.5.1
128.5.0
115.18.0
128.4.0
115.17.0
128.3.1
115.16.1
128.3.0
115.16.0
128.2.0
115.15.0
128.1.0
115.14.0
128.0
115.13.0
115.12.0
115.11.0
115.10.0
115.9.1
115.9.0
115.8.0
115.7.0
115.6.0
115.5.0
115.4.0
115.3.1
115.3.0
115.2.1
102.15.1
115.2.0
102.15.0
115.1.0
102.14.0
115.0.3
115.0.2
115.0.1
102.13.0
115.0
102.12.0
102.11.0
102.10.0
102.9.0
102.8.0
102.7.0
102.6.0
102.5.0
102.4.0
102.3.0
102.2.0
91.13.0
102.1.0
91.12.0
102.0.1
102.0
91.11.0
91.10.0
91.9.1
91.9.0
91.8.0
91.7.1
91.7.0
91.6.1
91.6.0
91.5.1
91.5.0
91.4.1
91.4.0
91.3.0
91.2.0
78.15.0
91.1.0
78.14.0
91.0.1
91.0
78.13.0
78.12.0
78.11.0
78.10.1
78.10.0
78.9.0
78.8.0
78.7.1
78.7.0
78.6.1
78.6.0
78.5.0
78.4.1
78.4.0
78.3.1
78.3.0
78.2.0
68.12.0
23
22
8.0
7.0
38.0.5
78.1.0
68.11.0
78.0.2
78.0.1
78.0
68.10.0
68.9.0
68.8.0
68.7.0
68.6.1
68.6.0
68.5.0
68.4.2
68.4.1
68.4.0
68.3.0
68.2.0
68.1.0
60.9.0
68.0.2
68.0.1
68.0
60.8.0
24.0.2
24.0.1
10.2
10.1
31.3
31.2
31.1
31.5
31.4
60.7.2
60.7.1
60.7.0
60.6.3
60.6.2
60.6.1
60.6.0
60.5.2
60.3.0
60.0.2
60.0.1
52.9.0
52.8.1
52.8.0
52.7.4
52.7.3
52.7.2
52.7.1
52.7.0
52.6.0
52.5.3
52.5.2
52.4.1
52.1.0
45.9.0
45.8.0
45.7.0
45.6.0
45.5.1
45.5.0
45.4.0
45.3.0
45.2.0
45.1.1
45.1.0
45.0.2
45.0.1
45.0
38.8.0
38.7.1
38.7.0
38.6.1
38.6.0
38.5.2
38.5.1
38.5.0
38.4.0
38.3.0
38.2.1
38.2.0
38.1.1
38.1.0
38.0.1
38.0
31.8.0
31.7.0
31.6.0
31.5.3
31.5.2
31.5.1
31.5.0
31.4.0
31.3.0
31.2.0
31.1.1
31.1.0
31.0
24.8.1
24.8.0
24.7.0
24.6.0
24.5.0
24.4.0
24.3.0
24.2.0
24.1.1
24.1.0
24.0
17.0.11
17.0.10
17.0.9
17.0.8
17.0.7
17.0.6
17.0.5
17.0.4
17.0.3
17.0.2
17.0.1
17.0
10.0.12
10.0.11
10.0.10
10.0.9
10.0.8
10.0.7
10.0.6
10.0.5
10.0.4
10.0.3
10.0.2
10.0.1
10.0
60.5.1
60.5.0
60.4.0
60.2.2
60.2.1
60.2.0
60.1.0
60.0
52.8
52.7
52.5.0
52.4.0
52.3.0
52.2.1
52.2.0
52.1.2
52.1.1
52.1
52.0.2
52.0.1
52.0
45.9
45.8
45.7
45.6
45.5
45.4
45.3
45.2
45.1
45
Vulnerabilities (998)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU138977 - Use After Free CVE-2026-16362 |
CWE-416 | High | 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138978 - Incorrect Calculation CVE-2026-16363 |
CWE-682 | High | 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138979 - Out-of-bounds read CVE-2026-16368 |
CWE-125 | Medium | 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138980 - Integer overflow CVE-2026-16369 |
CWE-190 | High | 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138981 - Improper Privilege Management CVE-2026-16371 |
CWE-269 | High | 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138982 - Exposure of sensitive information to an unauthorized actor CVE-2026-16374 |
CWE-200 | Medium | 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138983 - Protection Mechanism Failure CVE-2026-16375 |
CWE-693 | High | 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138964 - Improper Access Control CVE-2026-16349 |
CWE-284 | Medium | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138965 - Improper input validation CVE-2026-16350 |
CWE-20 | Medium | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138966 - Use After Free CVE-2026-16351 |
CWE-416 | High | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138967 - Use After Free CVE-2026-16352 |
CWE-416 | High | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138968 - NULL Pointer Dereference CVE-2026-16353 |
CWE-476 | Medium | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138969 - Exposure of sensitive information to an unauthorized actor CVE-2026-16354 |
CWE-200 | Medium | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138970 - Incorrect Calculation CVE-2026-16355 |
CWE-682 | High | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138971 - Use After Free CVE-2026-16356 |
CWE-416 | High | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138972 - Improper input validation CVE-2026-16357 |
CWE-20 | Medium | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138973 - Improper Access Control CVE-2026-16358 |
CWE-284 | Medium | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138974 - Improper input validation CVE-2026-16359 |
CWE-20 | Medium | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138975 - Memory corruption CVE-2026-16360 |
CWE-119 | High | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072302 and 12 more |
||
| #VU138976 - Memory corruption CVE-2026-16361 |
CWE-119 | High | 115.38.0, 140.13.0 | 21.07.2026 |
SB2026072201 SB2026072301 SB2026072442 and 11 more |
Showing elements 1 - 20 out of 998