Known vulnerabilities in Firefox ESR 128.12.0 - page 5

Vendor: Mozilla
Software: Firefox ESR
Version: 128.12.0
Software CPE: cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
Total vulnerabilities: 225
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Firefox ESR version 128.12.0 Firefox ESR 128.12.0 is affected by 225 vulnerabilities: 142 high, 65 medium, 18 low Critical High Medium Low

Vulnerabilities (225)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134604 - Improper Access Control
CVE-2026-12289
CWE-284 High
No
No
115.37.0, 140.12.0 16.06.2026 SB2026061653
SB2026061756
SB2026061757
and 28 more
#VU134605 - Memory corruption
CVE-2026-12290
CWE-119 High
No
No
115.37.0, 140.12.0 16.06.2026 SB2026061653
SB2026061756
SB2026061757
and 29 more
#VU134606 - Use After Free
CVE-2026-12291
CWE-416 High
No
No
115.37.0, 140.12.0 16.06.2026 SB2026061653
SB2026061756
SB2026061757
and 29 more
#VU131840 - Improper Privilege Management
CVE-2026-8955
CWE-269 High
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131841 - Integer overflow
CVE-2026-8956
CWE-190 Medium
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131842 - Improper Privilege Management
CVE-2026-8957
CWE-269 Low
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131843 - Improper Access Control
CVE-2026-8958
CWE-284 High
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131844 - Out-of-bounds read
CVE-2026-8959
CWE-125 Low
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052150
and 20 more
#VU131845 - Improper input validation
CVE-2026-8961
CWE-20 Medium
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131846 - Protection Mechanism Failure
CVE-2026-8962
CWE-693 Medium
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131847 - NULL Pointer Dereference
CVE-2026-8968
CWE-476 Medium
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131848 - Improper Privilege Management
CVE-2026-8970
CWE-269 Medium
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131849 - Memory corruption
CVE-2026-8974
CWE-119 High
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131837 - Integer overflow
CVE-2026-8949
CWE-190 Low
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052150
and 9 more
#VU131838 - Improper Access Control
CVE-2026-8950
CWE-284 High
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131839 - Integer overflow
CVE-2026-8954
CWE-190 Medium
No
No
140.11.0 19.05.2026 SB2026051930
SB2026051935
SB2026052102
and 35 more
#VU131833 - Out-of-bounds read
CVE-2026-8946
CWE-125 High
No
No
115.36.0, 140.11.0 19.05.2026 SB2026051929
SB2026051930
SB2026051935
and 36 more
#VU131835 - Use After Free
CVE-2026-8953
CWE-416 Medium
No
No
115.36.0, 140.11.0 19.05.2026 SB2026051929
SB2026051930
SB2026051935
and 35 more
#VU131768 - Protection Mechanism Failure
CVE-2026-8401
CWE-693 High
No
No
115.36.0, 140.11.0 18.05.2026 SB2026051267
SB2026051929
SB2026051930
and 34 more
#VU131171 - Improper input validation
CVE-2026-8391
CWE-20 High
No
No
115.36.0, 140.11.0 12.05.2026 SB2026051267
SB2026051929
SB2026051930
and 35 more


Showing elements 81 - 100 out of 225