Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2023-5171During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes,EPSS 1.0%CVE-2021-29971If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port EPSS 1.0%CVE-2021-29966Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2020-12406Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enEPSS 1.0%CVE-2020-6794If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessEPSS 1.0%CVE-2021-4129CRITICALMozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano rEPSS 1.0%CVE-2021-23972One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this EPSS 1.0%CVE-2020-15675When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. ThiEPSS 1.0%CVE-2018-18510The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the broEPSS 1.0%CVE-2016-9064Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who couEPSS 1.0%CVE-2021-23975The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this EPSS 1.0%CVE-2021-29981An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code thatEPSS 1.0%CVE-2020-12393The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the webEPSS 1.0%CVE-2021-29990Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of these bugs showed evidence of memory corEPSS 1.0%CVE-2021-29977Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2023-5169A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a poteEPSS 1.0%CVE-2021-23970Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerabEPSS 1.0%CVE-2021-23971When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have poEPSS 1.0%CVE-2022-29917CRITICALMozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in FirefoxEPSS 1.0%CVE-2021-38510The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's EPSS 1.0%