Firefox Esr

Vendor:

First CVE: Mar 14, 2012 · Active for 14 years

490
Total CVEs
More Total CVEs than 100% of tracked products
49.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Firefox Esr over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2012
14 years ago
Most Recent CVE
Oct 1, 2024
661 days ago

CVE Severity & Scoring

Firefox Esr490 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local16 (3.3%)
Network420 (85.7%)
Unknown54 (11.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low409 (83.5%)
High27 (5.5%)
Unknown54 (11.0%)
User Interaction
None85 (17.3%)
Unknown54 (11.0%)
Required351 (71.6%)
Privileges Required
Low11 (2.2%)
High0 (0.0%)
None425 (86.7%)
Unknown54 (11.0%)

Top CVEs

Signals from CVEs in this product scope (490 CVEs).

490 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi
May 21, 20153.776NOYES
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox
Dec 9, 20208.862NOYES
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code i
Dec 22, 20228.841NONO
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use
Feb 5, 20199.837NONO
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remo
Dec 19, 20238.836NONO
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x
Jul 23, 201410.036NONO
Unspecified vulnerability in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before
Sep 3, 201410.035NONO
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause
Jul 23, 201410.034NONO
If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulner
Dec 22, 20228.833NONO
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This
Dec 8, 202110.033NONO

Exploit Exposure

Signals from CVEs in this product scope (490 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.2% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (490 CVEs).

Media Mentions

Signals from CVEs in this product scope (490 CVEs).

Top CNAs Publishing CVEs For Firefox Esr

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
31.813.799.9%01
31.7.0168.94.2%00
31.6.0208.64.4%00
31.5297.93.9%00
31.4297.93.9%00
31.3297.93.9%00
31.2347.73.7%00
31.1297.93.9%00
24.8.017.516.2%00
24.729.75.3%00
24.689.75.1%00
24.5119.85.0%00
24.4119.85.0%00
24.3119.85.0%00
24.2119.85.0%00
128.119.80.6%00
128.088.00.6%00
10.266.32.8%00
10.166.32.8%00