Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2020-26973—Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer byEPSS 1.6%CVE-2019-11692—A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potenEPSS 1.6%CVE-2020-6812—The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites wiEPSS 1.6%CVE-2023-5724HIGHDrivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability afEPSS 1.6%CVE-2017-7813—Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usuEPSS 1.6%CVE-2021-43545—Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, FiEPSS 1.6%CVE-2018-5164—Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME typeEPSS 1.6%CVE-2020-15676—Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed aEPSS 1.6%CVE-2020-6796—A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. EPSS 1.6%CVE-2017-7831—A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism oEPSS 1.6%CVE-2018-5141—A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user intEPSS 1.6%CVE-2020-12390—Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.EPSS 1.6%CVE-2018-18512—A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediatelyEPSS 1.6%CVE-2018-5111—When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a differEPSS 1.6%CVE-2021-43541—When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerabilEPSS 1.6%CVE-2020-12425—Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential infoEPSS 1.6%CVE-2018-12400—In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows EPSS 1.6%CVE-2018-12399—When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registeEPSS 1.6%CVE-2020-26960—If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potenEPSS 1.6%CVE-2019-11691—A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called aEPSS 1.6%