Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2017-5392—Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and EPSS 1.8%CVE-2018-5107—The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The prEPSS 1.8%CVE-2017-5391—Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug wEPSS 1.8%CVE-2017-7848—RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.EPSS 1.8%CVE-2018-5170—It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote aEPSS 1.8%CVE-2017-5411—A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage caEPSS 1.8%CVE-2017-5379—Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects FireEPSS 1.8%CVE-2021-23994—A WebGL framebuffer was not initialized early enough, resulting in memory corruption and an out of bound write. This vulnerability affects FEPSS 1.8%CVE-2017-7844—A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determiEPSS 1.8%CVE-2019-17010—Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have cEPSS 1.8%CVE-2018-5126—Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume that with enough effoEPSS 1.7%CVE-2020-12410—Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corrEPSS 1.7%CVE-2019-9800—Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of EPSS 1.7%CVE-2019-11746—A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentEPSS 1.7%CVE-2021-38504—When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to EPSS 1.7%CVE-2019-11714—Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vuEPSS 1.7%CVE-2021-43542—Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. ThiEPSS 1.7%CVE-2017-7790—On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, stack memory data canEPSS 1.7%CVE-2017-5403—When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a EPSS 1.7%CVE-2019-9795—A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to triggEPSS 1.7%