Firefox Esr
Vendor:
First CVE: Mar 14, 2012 · Active for 14 years
490
Total CVEs
More Total CVEs than 100% of tracked products
49.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Firefox Esr over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2012
14 years ago
Most Recent CVE
Oct 1, 2024
661 days ago
CVE Severity & Scoring
Firefox Esr490 CVEs
41%
49%
9%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local16 (3.3%)
Network420 (85.7%)
Unknown54 (11.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low409 (83.5%)
High27 (5.5%)
Unknown54 (11.0%)
User Interaction
None85 (17.3%)
Unknown54 (11.0%)
Required351 (71.6%)
Privileges Required
Low11 (2.2%)
High0 (0.0%)
None425 (86.7%)
Unknown54 (11.0%)
Top CVEs
Signals from CVEs in this product scope (490 CVEs).
490 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-mi | May 21, 2015 | 3.7 | 76 | NO | YES |
CVE-2020-26950HIGH In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox | Dec 9, 2020 | 8.8 | 62 | NO | YES |
CVE-2022-1802HIGH If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code i | Dec 22, 2022 | 8.8 | 41 | NO | NO |
CVE-2018-18500CRITICAL A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use | Feb 5, 2019 | 9.8 | 37 | NO | NO |
CVE-2023-6856HIGH The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remo | Dec 19, 2023 | 8.8 | 36 | NO | NO |
CVE-2014-1544HIGH Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x | Jul 23, 2014 | 10.0 | 36 | NO | NO |
CVE-2014-1562HIGH Unspecified vulnerability in the browser engine in Mozilla Firefox before 32.0, Firefox ESR 24.x before 24.8 and 31.x before 31.1, and Thunderbird 24.x before 24.8 and 31.x before | Sep 3, 2014 | 10.0 | 35 | NO | NO |
CVE-2014-1547HIGH Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause | Jul 23, 2014 | 10.0 | 34 | NO | NO |
CVE-2022-2200HIGH If an object prototype was corrupted by an attacker, they would have been able to set undesired attributes on a JavaScript object, leading to privileged code execution. This vulner | Dec 22, 2022 | 8.8 | 33 | NO | NO |
CVE-2021-38503CRITICAL The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This | Dec 8, 2021 | 10.0 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (490 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
0.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
0.2% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (490 CVEs).
Media Mentions
Signals from CVEs in this product scope (490 CVEs).
Top CNAs Publishing CVEs For Firefox Esr
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 31.8 | 1 | 3.7 | 99.9% | 0 | 1 |
| 31.7.0 | 16 | 8.9 | 4.2% | 0 | 0 |
| 31.6.0 | 20 | 8.6 | 4.4% | 0 | 0 |
| 31.5 | 29 | 7.9 | 3.9% | 0 | 0 |
| 31.4 | 29 | 7.9 | 3.9% | 0 | 0 |
| 31.3 | 29 | 7.9 | 3.9% | 0 | 0 |
| 31.2 | 34 | 7.7 | 3.7% | 0 | 0 |
| 31.1 | 29 | 7.9 | 3.9% | 0 | 0 |
| 24.8.0 | 1 | 7.5 | 16.2% | 0 | 0 |
| 24.7 | 2 | 9.7 | 5.3% | 0 | 0 |
| 24.6 | 8 | 9.7 | 5.1% | 0 | 0 |
| 24.5 | 11 | 9.8 | 5.0% | 0 | 0 |
| 24.4 | 11 | 9.8 | 5.0% | 0 | 0 |
| 24.3 | 11 | 9.8 | 5.0% | 0 | 0 |
| 24.2 | 11 | 9.8 | 5.0% | 0 | 0 |
| 128.1 | 1 | 9.8 | 0.6% | 0 | 0 |
| 128.0 | 8 | 8.0 | 0.6% | 0 | 0 |
| 10.2 | 6 | 6.3 | 2.8% | 0 | 0 |
| 10.1 | 6 | 6.3 | 2.8% | 0 | 0 |