Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2019-11758Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed eEPSS 1.3%CVE-2020-6822On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is EPSS 1.3%CVE-2018-18513A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-ofEPSS 1.3%CVE-2020-26978Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as sEPSS 1.3%CVE-2016-9902The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. TEPSS 1.3%CVE-2018-12402The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loEPSS 1.3%CVE-2019-9801Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matchiEPSS 1.3%CVE-2021-23968If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation reEPSS 1.3%CVE-2020-6795When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leaEPSS 1.3%CVE-2021-29946Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when usedEPSS 1.3%CVE-2018-5140Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This coulEPSS 1.3%CVE-2020-26959During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruEPSS 1.3%CVE-2019-11734Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corEPSS 1.3%CVE-2020-26972The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting tEPSS 1.3%CVE-2020-26953It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishEPSS 1.3%CVE-2021-23960Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. ThisEPSS 1.3%CVE-2024-0743HIGHAn unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122,EPSS 1.3%CVE-2022-40959MEDIUMDuring iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissionEPSS 1.3%CVE-2017-5420A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an aEPSS 1.3%CVE-2019-9814Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corEPSS 1.3%