Firefox ESR
Mozilla- Software type
- —
- Catalog vulnerabilities
- 907
Severity across 9 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 9 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, Firefox ESR has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Firefox ESR and determine which vulnerabilities affect that version.
| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-5734Memory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 | Exploitation statusNot known exploited | FixYes | Published04/07/2026 | SeverityHigh |
CVE-2026-5732Incorrect boundary conditions, integer overflow in the Graphics: Text component | Exploitation statusNot known exploited | FixYes | Published04/07/2026 | SeverityHigh |
CVE-2026-5731Memory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2 | Exploitation statusNot known exploited | FixYes | Published04/07/2026 | SeverityCritical |
CVE-2026-4721Memory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4720Memory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149 | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4719Incorrect boundary conditions in the Graphics: Text component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4718Undefined behavior in the WebRTC: Signaling component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4717Privilege escalation in the Netmonitor component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4716Incorrect boundary conditions, uninitialized memory in the JavaScript Engine component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4715Uninitialized memory in the Graphics: Canvas2D component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4714Incorrect boundary conditions in the Audio/Video component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4713Incorrect boundary conditions in the Graphics component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4712Information disclosure in the Widget: Cocoa component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4711Use-after-free in the Widget: Cocoa component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4710Incorrect boundary conditions in the Audio/Video component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4709Incorrect boundary conditions in the Audio/Video: GMP component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4708Incorrect boundary conditions in the Graphics component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4707Incorrect boundary conditions in the Graphics: Canvas2D component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4706Incorrect boundary conditions in the Graphics: Canvas2D component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4705Undefined behavior in the WebRTC: Signaling component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4704Denial-of-service in the WebRTC: Signaling component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4702JIT miscompilation in the JavaScript Engine component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4701Use-after-free in the JavaScript Engine component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4700Mitigation bypass in the Networking: HTTP component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4699Incorrect boundary conditions in the Layout: Text and Fonts component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4698JIT miscompilation in the JavaScript Engine: JIT component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4697Incorrect boundary conditions in the Audio/Video: Web Codecs component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4696Use-after-free in the Layout: Text and Fonts component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4695Incorrect boundary conditions in the Audio/Video: Web Codecs component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4694Incorrect boundary conditions, integer overflow in the Graphics component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4693Incorrect boundary conditions in the Audio/Video: Playback component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4692Sandbox escape in the Responsive Design Mode component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4691Use-after-free in the CSS Parsing and Computation component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4690Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4689Sandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4688Sandbox escape due to use-after-free in the Disability Access APIs component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4687Sandbox escape due to incorrect boundary conditions in the Telemetry component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityCritical |
CVE-2026-4686Incorrect boundary conditions in the Graphics: Canvas2D component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4685Incorrect boundary conditions in the Graphics: Canvas2D component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-4684Race condition, use-after-free in the Graphics: WebRender component | Exploitation statusNot known exploited | FixYes | Published03/24/2026 | SeverityHigh |
CVE-2026-2793Memory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2792Memory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148 | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2791Mitigation bypass in the Networking: Cache component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2790Same-origin policy bypass in the Networking: JAR component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2789Use-after-free in the Graphics: ImageLib component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2788Incorrect boundary conditions in the Audio/Video: GMP component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2787Use-after-free in the DOM: Window and Location component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2786Use-after-free in the JavaScript Engine component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2785Invalid pointer in the JavaScript Engine component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2784Mitigation bypass in the DOM: Security component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2783Information disclosure due to JIT miscompilation in the JavaScript Engine: JIT component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityMedium |
CVE-2026-2782Privilege escalation in the Netmonitor component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2781Integer overflow in the Libraries component in NSS | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2780Privilege escalation in the Netmonitor component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2779Incorrect boundary conditions in the Networking: JAR component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2778Sandbox escape due to incorrect boundary conditions in the DOM: Core & HTML component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2777Privilege escalation in the Messaging System component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2776Sandbox escape due to incorrect boundary conditions in the Telemetry component in External Software | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2775Mitigation bypass in the DOM: HTML Parser component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2774Integer overflow in the Audio/Video component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2773Incorrect boundary conditions in the Web Audio component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2772Use-after-free in the Audio/Video: Playback component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2771Undefined behavior in the DOM: Core & HTML component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2770Use-after-free in the DOM: Bindings (WebIDL) component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2769Use-after-free in the Storage: IndexedDB component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2768Sandbox escape in the Storage: IndexedDB component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2767Use-after-free in the JavaScript: WebAssembly component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityHigh |
CVE-2026-2766Use-after-free in the JavaScript Engine: JIT component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2765Use-after-free in the JavaScript Engine component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2764JIT miscompilation, use-after-free in the JavaScript Engine: JIT component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2763Use-after-free in the JavaScript Engine component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2762Integer overflow in the JavaScript: Standard Library component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2761Sandbox escape in the Graphics: WebRender component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2760Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2759Incorrect boundary conditions in the Graphics: ImageLib component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2758Use-after-free in the JavaScript: GC component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2757Incorrect boundary conditions in the WebRTC: Audio/Video component | Exploitation statusNot known exploited | FixYes | Published02/24/2026 | SeverityCritical |
CVE-2026-2447Heap buffer overflow in libvpx | Exploitation statusNot known exploited | FixYes | Published02/16/2026 | SeverityHigh |
CVE-2026-0891Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147 | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityHigh |
CVE-2026-0890Spoofing issue in the DOM: Copy & Paste and Drag & Drop component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityMedium |
CVE-2026-0887Clickjacking issue, information disclosure in the PDF Viewer component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityMedium |
CVE-2026-0886Incorrect boundary conditions in the Graphics component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityMedium |
CVE-2026-0885Use-after-free in the JavaScript: GC component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityMedium |
CVE-2026-0884Use-after-free in the JavaScript Engine component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityCritical |
CVE-2026-0883Information disclosure in the Networking component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityMedium |
CVE-2026-0882Use-after-free in the IPC component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityHigh |
CVE-2026-0880Sandbox escape due to integer overflow in the Graphics component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityHigh |
CVE-2026-0879Sandbox escape due to incorrect boundary conditions in the Graphics component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityCritical |
CVE-2026-0878Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityHigh |
CVE-2026-0877Mitigation bypass in the DOM: Security component | Exploitation statusNot known exploited | FixYes | Published01/13/2026 | SeverityHigh |
CVE-2025-14333Memory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146 | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityHigh |
CVE-2025-14331Same-origin policy bypass in the Request Handling component | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityMedium |
CVE-2025-14330JIT miscompilation in the JavaScript Engine: JIT component | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityCritical |
CVE-2025-14329Privilege escalation in the Netmonitor component | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityHigh |
CVE-2025-14328Privilege escalation in the Netmonitor component | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityHigh |
CVE-2025-14327Spoofing issue in the Downloads Panel component | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityHigh |
CVE-2025-14325JIT miscompilation in the JavaScript Engine: JIT component | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityHigh |
CVE-2025-14324JIT miscompilation in the JavaScript Engine: JIT component | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityCritical |
CVE-2025-14323Privilege escalation in the DOM: Notifications component | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityHigh |
CVE-2025-14322Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component | Exploitation statusNot known exploited | FixYes | Published12/09/2025 | SeverityHigh |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan