Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2021-29983—Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: TEPSS 0.7%CVE-2024-3854HIGHIn some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affectEPSS 0.7%CVE-2019-11695—A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be alloEPSS 0.7%CVE-2023-4055—When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent witEPSS 0.7%CVE-2019-17002—If upgrade-insecure-requests was specified in the Content Security Policy, and a link was dragged and dropped from that page, the link was nEPSS 0.7%CVE-2023-32207HIGHA missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerabiEPSS 0.7%CVE-2022-42929MEDIUMIf a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browseEPSS 0.7%CVE-2022-45418MEDIUMIf a custom mouse cursor is specified in CSS, under certain circumstances the cursor could have been drawn over the browser UI, resulting inEPSS 0.7%CVE-2021-29993—Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug onlyEPSS 0.7%CVE-2022-29916MEDIUMFirefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been usEPSS 0.7%CVE-2022-46878HIGHMozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in ThunderbirEPSS 0.7%CVE-2022-46881HIGHAn optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash.
*Note*: TEPSS 0.7%CVE-2022-34482HIGHAn attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contaEPSS 0.7%CVE-2022-34483HIGHAn attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contaEPSS 0.7%CVE-2020-15649—Given an installed malicious file picker application, an attacker was able to steal and upload local files of their choosing, regardless of EPSS 0.7%CVE-2021-23996—By utilizing 3D CSS in conjunction with Javascript, content could have been rendered outside the webpage's viewport, resulting in a spoofingEPSS 0.7%CVE-2024-8384CRITICALThe JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two paEPSS 0.7%CVE-2023-28176HIGHMemory safety bugs present in Firefox 110 and Firefox ESR 102.8. Some of these bugs showed evidence of memory corruption and we presume thatEPSS 0.7%CVE-2024-1546HIGHWhen storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memoEPSS 0.7%CVE-2022-1196MEDIUMAfter a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable EPSS 0.7%