Known vulnerabilities in Firefox ESR 128.2.0 - page 9

Vendor: Mozilla
Software: Firefox ESR
Version: 128.2.0
Software CPE: cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
Total vulnerabilities: 281
Public exploits: 3
Known exploited (KEV): 1
Highest CVSSv4 Score: 8.7

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Firefox ESR version 128.2.0 Firefox ESR 128.2.0 is affected by 281 vulnerabilities: 1 critical, 160 high, 83 medium, 37 low Critical High Medium Low

Vulnerabilities (281)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU119418 - Memory corruption
CVE-2025-14333
CWE-119 High
No
No
140.6.0 09.12.2025 SB2025120939
SB20251210189
SB20251210190
and 40 more
#VU118263 - Use After Free
CVE-2025-13020
CWE-416 Low
No
No
140.5.0 11.11.2025 SB2025111145
SB2025111260
SB2025111303
and 36 more
#VU118262 - Protection Mechanism Failure
CVE-2025-13019
CWE-693 Medium
No
No
140.5.0 11.11.2025 SB2025111145
SB2025111260
SB2025111303
and 36 more
#VU118261 - Protection Mechanism Failure
CVE-2025-13018
CWE-693 Medium
No
No
140.5.0 11.11.2025 SB2025111145
SB2025111260
SB2025111303
and 36 more
#VU118260 - Protection Mechanism Failure
CVE-2025-13017
CWE-693 Medium
No
No
140.5.0 11.11.2025 SB2025111145
SB2025111260
SB2025111303
and 36 more
#VU118259 - Memory corruption
CVE-2025-13016
CWE-119 High
No
No
140.5.0 11.11.2025 SB2025111145
SB2025111260
SB2025111303
and 36 more
#VU118258 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2025-13015
CWE-451 Low
No
No
115.30.0, 140.5.0 11.11.2025 SB2025111145
SB2025111260
SB2025111303
and 36 more
#VU118257 - Use After Free
CVE-2025-13014
CWE-416 Low
No
No
115.30.0, 140.5.0 11.11.2025 SB2025111145
SB2025111260
SB2025111303
and 36 more
#VU118256 - Protection Mechanism Failure
CVE-2025-13013
CWE-693 Medium
No
No
115.30.0, 140.5.0 11.11.2025 SB2025111145
SB2025111260
SB2025111303
and 36 more
#VU118255 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2025-13012
CWE-362 High
No
No
115.30.0, 140.5.0 11.11.2025 SB2025111145
SB2025111260
SB2025111303
and 36 more
#VU116998 - Memory corruption
CVE-2025-11715
CWE-119 High
No
No
140.4.0 14.10.2025 SB2025101454
SB2025101455
SB2025101456
and 35 more
#VU116997 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-11713
CWE-94 High
No
No
140.4.0 14.10.2025 SB2025101454
SB2025101455
SB2025101456
and 6 more
#VU116996 - Protection Mechanism Failure
CVE-2025-11712
CWE-693 Low
No
No
140.4.0 14.10.2025 SB2025101454
SB2025101455
SB2025101456
and 35 more
#VU116995 - Use After Free
CVE-2025-11708
CWE-416 High
No
No
140.4.0 14.10.2025 SB2025101454
SB2025101455
SB2025101456
and 35 more
#VU116994 - Memory corruption
CVE-2025-11714
CWE-119 High
No
No
115.29.0, 140.4.0 14.10.2025 SB2025101454
SB2025101455
SB2025101456
and 35 more
#VU116993 - Permissions, Privileges, and Access Controls
CVE-2025-11711
CWE-264 High
No
No
115.29.0, 140.4.0 14.10.2025 SB2025101454
SB2025101455
SB2025101456
and 35 more
#VU116992 - Exposure of sensitive information to an unauthorized actor
CVE-2025-11710
CWE-200 Medium
No
No
115.29.0, 140.4.0 14.10.2025 SB2025101454
SB2025101455
SB2025101456
and 35 more
#VU116991 - Out-of-bounds write
CVE-2025-11709
CWE-787 High
No
No
115.29.0, 140.4.0 14.10.2025 SB2025101454
SB2025101455
SB2025101456
and 35 more
#VU115728 - Memory corruption
CVE-2025-10528
CWE-119 High
No
No
140.3.0 17.09.2025 SB2025091769
SB2025091770
SB2025091771
and 36 more
#VU115727 - Use After Free
CVE-2025-10527
CWE-416 High
No
No
140.3.0 17.09.2025 SB2025091769
SB2025091770
SB2025091771
and 36 more


Showing elements 161 - 180 out of 281