Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2023-5725—A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive useEPSS 0.9%CVE-2024-11704CRITICALA double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the sEPSS 0.9%CVE-2019-11761—By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact fEPSS 0.9%CVE-2021-29991—Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attEPSS 0.9%CVE-2019-9798—On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow maliciouEPSS 0.9%CVE-2022-38478HIGHMembers the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of theseEPSS 0.9%CVE-2020-6830—For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That toEPSS 0.9%CVE-2021-4127CRITICALAn out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects ThuEPSS 0.9%CVE-2019-11739—Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerabiEPSS 0.9%CVE-2023-34414—The error page for sites with invalid TLS certificates was missing the
activation-delay Firefox uses to protect prompts and permission dialoEPSS 0.9%CVE-2017-5393—The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could EPSS 0.9%CVE-2019-11749—A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal EPSS 0.9%CVE-2022-46871HIGHAn out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.EPSS 0.9%CVE-2022-38477HIGHMozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some oEPSS 0.9%CVE-2023-4582HIGHBuffer Overflow in WebGL glGetProgramivEPSS 0.9%CVE-2023-4057—Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruptionEPSS 0.9%CVE-2023-6865—`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local EPSS 0.9%CVE-2024-2614HIGHMemory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruptionEPSS 0.9%CVE-2021-23962—Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerabilitEPSS 0.9%CVE-2022-40956MEDIUMWhen injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. EPSS 0.9%