Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2024-10464HIGHRepeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressEPSS 0.6%CVE-2024-0747MEDIUMWhen a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child ContEPSS 0.6%CVE-2026-8949HIGHInteger overflow in the Widget: Win32 componentEPSS 0.6%CVE-2026-74977HIGHInteger overflow in the Graphics componentEPSS 0.6%CVE-2023-5170—In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileEPSS 0.6%CVE-2024-10459MEDIUMAn attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerabilitEPSS 0.6%CVE-2024-7525CRITICALIt was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response EPSS 0.6%CVE-2026-2767HIGHUse-after-free in the JavaScript: WebAssembly componentEPSS 0.6%CVE-2026-2765CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2026-2763CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2026-2766CRITICALUse-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2020-12397—By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird dispEPSS 0.6%CVE-2026-2758CRITICALUse-after-free in the JavaScript: GC componentEPSS 0.6%CVE-2026-2764CRITICALJIT miscompilation, use-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-2770HIGHUse-after-free in the DOM: Bindings (WebIDL) componentEPSS 0.6%CVE-2026-2772HIGHUse-after-free in the Audio/Video: Playback componentEPSS 0.6%CVE-2024-10467CRITICALMemory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruptionEPSS 0.6%CVE-2026-4698HIGHJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-4721CRITICALMemory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149EPSS 0.6%CVE-2025-14321CRITICALUse-after-free in the WebRTC: Signaling componentEPSS 0.6%