Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2019-17016—When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This EPSS 2.0%CVE-2018-5112—Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but thisEPSS 2.0%CVE-2018-12367—In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure preEPSS 2.0%CVE-2017-7846—It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website"EPSS 2.0%CVE-2017-5425—The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access tEPSS 2.0%CVE-2020-15673—Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corrEPSS 2.0%CVE-2016-9896—Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability aEPSS 2.0%CVE-2018-18508—In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulEPSS 2.0%CVE-2018-5162—Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52EPSS 2.0%CVE-2017-7821—A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered withoutEPSS 2.0%CVE-2020-12422—In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out oEPSS 1.9%CVE-2018-18495—WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. TEPSS 1.9%CVE-2017-5421—A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what siteEPSS 1.9%CVE-2017-7762—When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used forEPSS 1.9%CVE-2016-9070—A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScripEPSS 1.9%CVE-2019-17005—The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the EPSS 1.9%CVE-2025-2857CRITICALIncorrect handle could lead to sandbox escapesEPSS 1.9%CVE-2017-7780—Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume that with enough effoEPSS 1.9%CVE-2020-15678—When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This EPSS 1.9%CVE-2016-9071—Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a uEPSS 1.9%