Vulnerabilities in Mozilla

2,105 results
Vexday analysis

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-0879CRITICALSandbox escape due to incorrect boundary conditions in the Graphics componentEPSS 0.6%CVE-2025-0237MEDIUMWebChannel APIs susceptible to confused deputy attackEPSS 0.6%CVE-2023-25752—When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may haEPSS 0.6%CVE-2026-5731CRITICALMemory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2EPSS 0.6%CVE-2022-45404MEDIUMThrough a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing theEPSS 0.6%CVE-2026-2788CRITICALIncorrect boundary conditions in the Audio/Video: GMP componentEPSS 0.6%CVE-2024-2611MEDIUMA missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerabilEPSS 0.6%CVE-2019-11762—If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/EPSS 0.6%CVE-2026-74988CRITICALInternally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154EPSS 0.6%CVE-2024-7527HIGHUnexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR <EPSS 0.6%CVE-2024-0744HIGHIn some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulEPSS 0.6%CVE-2026-74940CRITICALUse-after-free in the Graphics: Text componentEPSS 0.6%CVE-2026-74943CRITICALUse-after-free in the Graphics: ImageLib componentEPSS 0.6%CVE-2021-24000—A race condition with requestPointerLock() and setTimeout() could have resulted in a user interacting with one tab when they believed they wEPSS 0.6%CVE-2026-0889HIGHDenial-of-service in the DOM: Service Workers componentEPSS 0.6%CVE-2026-6749HIGHInformation disclosure due to uninitialized memory in the Graphics: Canvas2D componentEPSS 0.6%CVE-2024-10458MEDIUMA permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects EPSS 0.6%CVE-2026-7320HIGHInformation disclosure due to incorrect boundary conditions in the Audio/Video componentEPSS 0.6%CVE-2024-2609MEDIUMThe permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websiEPSS 0.6%CVE-2026-8946HIGHIncorrect boundary conditions in the Audio/Video: Web Codecs componentEPSS 0.6%