Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2018-5155A use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. This results in a potentially exploitEPSS 3.4%CVE-2018-12392When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable cEPSS 3.4%CVE-2017-5429Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of EPSS 3.4%CVE-2017-5410Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweepinEPSS 3.4%CVE-2017-7819A use-after-free vulnerability can occur in design mode when image objects are resized if objects referenced during the resizing have been fEPSS 3.4%CVE-2017-7818A use-after-free vulnerability can occur when manipulating arrays of Accessible Rich Internet Applications (ARIA) elements within containersEPSS 3.4%CVE-2018-18501Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed eEPSS 3.4%CVE-2018-12377A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deEPSS 3.4%CVE-2018-12378A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload EPSS 3.4%CVE-2017-5378Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered thrEPSS 3.4%CVE-2018-5091A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially explEPSS 3.4%CVE-2017-7826Memory safety bugs were reported in Firefox 56 and Firefox ESR 52.4. Some of these bugs showed evidence of memory corruption and we presume EPSS 3.3%CVE-2018-5089Memory safety bugs were reported in Firefox 57 and Firefox ESR 52.5. Some of these bugs showed evidence of memory corruption and we presume EPSS 3.3%CVE-2020-6811The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the webEPSS 3.3%CVE-2016-9897Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array withinEPSS 3.3%CVE-2018-5144An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerabilEPSS 3.3%CVE-2018-12407A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with theEPSS 3.3%CVE-2018-5154A use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths. This results in a potentially eEPSS 3.3%CVE-2017-5373Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presumEPSS 3.3%CVE-2017-5428An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimenEPSS 3.2%