Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2018-5138A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser paEPSS 1.1%CVE-2017-5417When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the addressbar so that tEPSS 1.1%CVE-2021-43535A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a poteEPSS 1.1%CVE-2019-9797Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the imageEPSS 1.1%CVE-2024-2607HIGHReturn registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A sEPSS 1.1%CVE-2021-38495Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and wEPSS 1.1%CVE-2022-40958MEDIUMBy injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus ovEPSS 1.1%CVE-2020-6808When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is thenEPSS 1.1%CVE-2021-38502Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercEPSS 1.1%CVE-2020-15647A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitiveEPSS 1.1%CVE-2017-5453A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed'sEPSS 1.1%CVE-2021-23976When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed deEPSS 1.1%CVE-2019-17014If an image had not loaded correctly (such as when it is not actually an image), it could be dragged and dropped cross-domain, resulting in EPSS 1.1%CVE-2018-18499A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a reEPSS 1.1%CVE-2023-6859A use-after-free condition affected TLS socket creation when under memory pressure. This vulnerability affects Firefox ESR < 115.6, ThunderbEPSS 1.1%CVE-2020-15681When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten anothEPSS 1.1%CVE-2022-40957MEDIUMInconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affEPSS 1.1%CVE-2019-11720Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This aEPSS 1.1%CVE-2019-9806A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediaEPSS 1.1%CVE-2017-7782An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protecEPSS 1.1%