Known vulnerabilities in Firefox ESR - page 29

Vendor: Mozilla
Software: Firefox ESR
Software CPE: cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
Total vulnerabilities: 998
Public exploits: 30
Known exploited (KEV): 13
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Firefox ESR Firefox ESR is affected by 998 known vulnerabilities: 11 critical, 508 high, 266 medium, 213 low Critical High Medium Low

Vulnerabilities (998)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU67788 - Out-of-bounds read
CVE-2022-3266
CWE-125 High
No
No
102.3.0 02.10.2022 SB2022092029
SB2022100204
SB2022102745
and 3 more
#VU67505 - Memory corruption
CVE-2022-40962
CWE-119 High
No
No
102.3.0 20.09.2022 SB2022092029
SB2022092120
SB2022092137
and 29 more
#VU67504 - Improper input validation
CVE-2022-40957
CWE-20 Medium
No
No
102.3.0 20.09.2022 SB2022092029
SB2022092120
SB2022092137
and 28 more
#VU67503 - Security Features
CVE-2022-40956
CWE-254 Medium
No
No
102.3.0 20.09.2022 SB2022092029
SB2022092120
SB2022092137
and 30 more
#VU66725 - Use After Free
CVE-2022-38476
CWE-416 Low
No
No
102.2.0 23.08.2022 SB2022082315
SB2022082316
SB2022082515
and 27 more
#VU66724 - Memory corruption
CVE-2022-38478
CWE-119 High
No
No
91.13.0, 102.2.0 23.08.2022 SB2022082315
SB2022082316
SB2022082411
and 36 more
#VU66723 - Memory corruption
CVE-2022-38477
CWE-119 High
No
No
102.2.0 23.08.2022 SB2022082315
SB2022082316
SB2022082502
and 28 more
#VU66720 - Permissions, Privileges, and Access Controls
CVE-2022-38473
CWE-264 Medium
No
No
91.13.0, 102.2.0 23.08.2022 SB2022082315
SB2022082316
SB2022082411
and 36 more
#VU66719 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-38472
CWE-451 Medium
No
No
91.13.0, 102.2.0 23.08.2022 SB2022082315
SB2022082316
SB2022082411
and 35 more
#VU65796 - Memory corruption
CVE-2022-2505
CWE-119 High
No
No
102.1.0 26.07.2022 SB2022072633
SB2022072841
SB2022072906
and 25 more
#VU65795 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-36318
CWE-79 Medium
No
No
91.12.0, 102.1.0 26.07.2022 SB2022072633
SB2022072634
SB2022072815
and 36 more
#VU65794 - Exposure of resource to wrong sphere
CVE-2022-36314
CWE-668 Low
No
No
102.1.0 26.07.2022 SB2022072633
SB2022072906
SB2022091450
and 4 more
#VU65793 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2022-36319
CWE-451 Low
No
No
91.12.0, 102.1.0 26.07.2022 SB2022072633
SB2022072634
SB2022072815
and 36 more
#VU64761 - Improper Authorization in Handler for Custom URL Scheme
CVE-2022-34478
CWE-939 Medium
No
No
91.11.0 29.06.2022 SB2022062901
SB2022062902
SB2022062903
and 14 more
#VU64760 - Error Handling
CVE-2022-34472
CWE-388 Low
No
No
91.11.0 29.06.2022 SB2022062901
SB2022062902
SB2022062903
and 38 more
#VU64756 - Integer overflow
CVE-2022-34481
CWE-190 Medium
No
No
91.11.0 29.06.2022 SB2022062901
SB2022062902
SB2022062903
and 42 more
#VU64752 - Security Features
CVE-2022-34468
CWE-254 Medium
No
No
91.11.0 28.06.2022 SB2022062901
SB2022062902
SB2022062903
and 37 more
#VU64751 - Use After Free
CVE-2022-34470
CWE-416 High
No
No
91.11.0 28.06.2022 SB2022062901
SB2022062902
SB2022062903
and 37 more
#VU64750 - Improper Restriction of Rendered UI Layers or Frames
CVE-2022-34479
CWE-1021 Medium
No
No
91.11.0 28.06.2022 SB2022062901
SB2022062902
SB2022062903
and 37 more
#VU63881 - Security Features
CVE-2022-31744
CWE-254 Medium
No
No
91.11.0 31.05.2022 SB2022053116
SB2022061323
SB2022062901
and 32 more


Showing elements 561 - 580 out of 998