Skip to main content

Vendor/product archive

mozilla / firefox_esr CVEs

Beta · best-effort

490 CVEs tagged to mozilla / firefox_esr68 Critical, 216 High, 202 Medium, 4 Low, 0 Unrated.

CVE-2024-8385

Published Sep 3, 2024

A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130,…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8384

Published Sep 3, 2024

The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory cor…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-8383

Published Sep 3, 2024

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8382

Published Sep 3, 2024

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8381

Published Sep 3, 2024

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox <…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-7531

Published Aug 6, 2024

Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affect…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7524

Published Aug 6, 2024

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic"…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 490 CVEsPage 1 of 20