Mozilla

Firefox ESR

866 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Published 22.07.2025 20:49:26
  • Last modified 28.07.2025 18:40:44

XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

  • EPSS 0.03%
  • Published 22.07.2025 20:49:26
  • Last modified 29.09.2025 23:03:01

Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

  • EPSS 0.05%
  • Published 22.07.2025 20:49:25
  • Last modified 28.07.2025 18:38:03

Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13...

  • EPSS 0.05%
  • Published 22.07.2025 20:49:25
  • Last modified 29.09.2025 23:02:08

Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebinding. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderbird < 141, and Thunderbird < 140.1.

  • EPSS 0.02%
  • Published 22.07.2025 20:49:25
  • Last modified 28.07.2025 18:51:21

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attribute. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, T...

  • EPSS 0.05%
  • Published 22.07.2025 20:49:24
  • Last modified 28.07.2025 18:30:57

On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 14...

  • EPSS 0.07%
  • Published 22.07.2025 20:49:24
  • Last modified 28.07.2025 18:32:21

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141, Firefox ESR < 115.2...

  • EPSS 0.05%
  • Published 22.07.2025 20:49:24
  • Last modified 29.09.2025 23:00:54

Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.

  • EPSS 0.07%
  • Published 24.06.2025 12:28:01
  • Last modified 14.07.2025 19:15:34

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a website vulnerable to a cross-site scripting attack. ...

  • EPSS 0.03%
  • Published 24.06.2025 12:28:00
  • Last modified 14.07.2025 19:15:33

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140, Firefox ESR < 128.12, T...