Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2020-26970—When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one bEPSS 1.2%CVE-2021-38493—Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corEPSS 1.2%CVE-2023-5176CRITICALMemory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruptionEPSS 1.2%CVE-2019-11718—Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream EPSS 1.2%CVE-2020-26956—In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerabiliEPSS 1.2%CVE-2020-15666—When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MEPSS 1.2%CVE-2021-29976—Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bugs showed evidence ofEPSS 1.2%CVE-2020-6813—When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attackerEPSS 1.2%CVE-2017-7814—File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware ProtectionEPSS 1.2%CVE-2019-9789—Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corEPSS 1.2%CVE-2020-26969—Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.2%CVE-2017-5452—Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTMLEPSS 1.2%CVE-2018-5142—If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not prEPSS 1.2%CVE-2021-23969—As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file isEPSS 1.2%CVE-2021-43534—Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of these bugs showed eEPSS 1.2%CVE-2025-1009CRITICALUse-after-free in XSLTEPSS 1.2%CVE-2021-29945—The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue oEPSS 1.2%CVE-2021-29969—If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected IMAP server responses prior to the completionEPSS 1.2%CVE-2017-7777—Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.EPSS 1.2%CVE-2019-11763—Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could haveEPSS 1.2%