Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2021-23988—Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.1%CVE-2019-11755—A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signatureEPSS 1.1%CVE-2020-15670—Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption anEPSS 1.1%CVE-2024-5688HIGHIf a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability aEPSS 1.1%CVE-2022-34470CRITICALSession history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, FiEPSS 1.1%CVE-2019-11751—Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks oEPSS 1.1%CVE-2022-45406CRITICALIf an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on EPSS 1.1%CVE-2021-23953—If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said informaEPSS 1.1%CVE-2022-31736CRITICALA malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects ThunderEPSS 1.1%CVE-2020-26951—A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker alreEPSS 1.1%CVE-2021-38505—Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to theEPSS 1.1%CVE-2021-38501—Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corrEPSS 1.0%CVE-2019-11712—POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allowEPSS 1.0%CVE-2019-17019—When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of beiEPSS 1.0%CVE-2021-29972—A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, aEPSS 1.0%CVE-2023-6863—The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destrEPSS 1.0%CVE-2020-35114—Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2021-23991—If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updateEPSS 1.0%CVE-2020-6810—After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the broEPSS 1.0%CVE-2019-11748—WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party cEPSS 1.0%