Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2021-23981—A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memoEPSS 1.1%CVE-2016-9903—Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resoEPSS 1.1%CVE-2017-7839—Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasteEPSS 1.1%CVE-2017-7840—JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resEPSS 1.1%CVE-2020-15648—Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This EPSS 1.1%CVE-2019-17020—If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not beEPSS 1.1%CVE-2017-7763—Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domaEPSS 1.1%CVE-2018-12406—Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corEPSS 1.1%CVE-2017-7770—A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendereEPSS 1.1%CVE-2019-9802—If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded daEPSS 1.1%CVE-2019-11724—Application permissions give additional remote troubleshooting permission to the site input.mozilla.org, which has been retired and now rediEPSS 1.1%CVE-2018-12370—In Reader View SameSite cookie protections are not checked on exiting. This allows for a payload to be triggered when Reader View is exited EPSS 1.1%CVE-2023-4046—In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilationEPSS 1.1%CVE-2021-29982—Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the potential leak of a singlEPSS 1.1%CVE-2020-15669—When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a useEPSS 1.1%CVE-2019-9799—Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory EPSS 1.1%CVE-2019-11728—The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a usEPSS 1.1%CVE-2022-29167HIGHReDoS vulnerability in header parsing in hawkEPSS 1.1%CVE-2021-23984—A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fEPSS 1.1%CVE-2011-2668—Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length headerEPSS 1.1%