Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2023-4056Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bEPSS 0.9%CVE-2020-15680If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken imEPSS 0.9%CVE-2022-40960MEDIUMConcurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitaEPSS 0.9%CVE-2024-1548MEDIUMA website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion anEPSS 0.9%CVE-2021-29987After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a differentEPSS 0.9%CVE-2021-29957If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unprotected part, ThundEPSS 0.9%CVE-2023-29542CRITICALA newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such asEPSS 0.9%CVE-2018-5143URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks,EPSS 0.9%CVE-2022-34468HIGHAn iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affecEPSS 0.9%CVE-2017-5389WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using hostEPSS 0.9%CVE-2022-26384CRITICALIf an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they werEPSS 0.9%CVE-2023-4048An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability aEPSS 0.9%CVE-2023-34416Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruptiEPSS 0.9%CVE-2023-5168CRITICALA compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potenEPSS 0.9%CVE-2022-22756HIGHIf a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an exeEPSS 0.9%CVE-2021-23979Mozilla developers reported memory safety bugs present in Firefox 85. Some of these bugs showed evidence of memory corruption and we presumeEPSS 0.9%CVE-2020-26964If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could EPSS 0.9%CVE-2022-46882CRITICALA use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESEPSS 0.9%CVE-2023-32214Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects WindoEPSS 0.9%CVE-2022-1097MEDIUM<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leadingEPSS 0.9%