Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2018-12358—Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malicious site to read resEPSS 1.3%CVE-2021-38500—Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corrEPSS 1.3%CVE-2018-5106—Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error lEPSS 1.3%CVE-2021-29989—Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corEPSS 1.3%CVE-2021-43528—Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not rEPSS 1.3%CVE-2020-12415—When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a suEPSS 1.3%CVE-2021-24002—When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and EPSS 1.3%CVE-2021-29986—A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affEPSS 1.3%CVE-2017-5381—The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashEPSS 1.3%CVE-2020-15652—By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This appliEPSS 1.3%CVE-2020-26965—Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typedEPSS 1.3%CVE-2017-5418—An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the readiEPSS 1.3%CVE-2017-7816—WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow thEPSS 1.3%CVE-2017-7812—If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be alEPSS 1.3%CVE-2020-35112—If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable fileEPSS 1.3%CVE-2016-5298—A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when tEPSS 1.3%CVE-2019-17025—Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.3%CVE-2019-11750—A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 andEPSS 1.3%CVE-2016-9069—A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability afEPSS 1.3%CVE-2020-26970—When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one bEPSS 1.2%