Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2023-5174CRITICALIf Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting inEPSS 1.0%CVE-2022-22738HIGHApplying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially EPSS 1.0%CVE-2021-23956—An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. EPSS 1.0%CVE-2024-6602CRITICALMemory corruption in NSSEPSS 1.0%CVE-2023-5731—Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 1.0%CVE-2019-17013—Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2022-34484HIGHThe Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruEPSS 1.0%CVE-2020-12398—If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue witEPSS 1.0%CVE-2020-12407—Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visEPSS 1.0%CVE-2023-29531CRITICALAn attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crEPSS 1.0%CVE-2024-2612HIGHIf an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveragEPSS 1.0%CVE-2021-23965—Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2023-5732—Address bar spoofing via bidirectional charactersEPSS 1.0%CVE-2021-29975—Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlEPSS 1.0%CVE-2020-15646—If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanEPSS 1.0%CVE-2022-22740HIGHCertain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causiEPSS 1.0%CVE-2020-12408—When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the addEPSS 1.0%CVE-2023-6860—The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. ThisEPSS 1.0%CVE-2019-9818—A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-EPSS 1.0%CVE-2023-6862—A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affeEPSS 1.0%