Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2026-8968HIGHDenial-of-service due to invalid pointer in the Audio/Video: Web Codecs componentEPSS 0.5%CVE-2026-4719HIGHIncorrect boundary conditions in the Graphics: Text componentEPSS 0.5%CVE-2026-4708HIGHIncorrect boundary conditions in the Graphics componentEPSS 0.5%CVE-2026-4704HIGHDenial-of-service in the WebRTC: Signaling componentEPSS 0.5%CVE-2026-4713HIGHIncorrect boundary conditions in the Graphics componentEPSS 0.5%CVE-2026-4714HIGHIncorrect boundary conditions in the Audio/Video componentEPSS 0.5%CVE-2026-6786HIGHMemory safety bugs fixed in Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150EPSS 0.5%CVE-2024-10462HIGHTruncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < EPSS 0.5%CVE-2026-6785HIGHMemory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150EPSS 0.5%CVE-2024-10465HIGHA clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR EPSS 0.5%CVE-2024-1549MEDIUMIf a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in usEPSS 0.5%CVE-2022-45414HIGHIf a Thunderbird user quoted from an HTML email, for example by replying to the email, and the email contained either a VIDEO tag with the PEPSS 0.5%CVE-2025-1931HIGHUse-after-free in WebTransportChildEPSS 0.5%CVE-2021-43532—The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authenticatioEPSS 0.5%CVE-2026-74985CRITICALPrivilege escalation in the Enterprise Policies componentEPSS 0.5%CVE-2022-29918HIGHMozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99. Some of thEPSS 0.5%CVE-2024-7529HIGHThe date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. EPSS 0.5%CVE-2024-11702HIGHCopying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-baseEPSS 0.5%CVE-2026-6771CRITICALMitigation bypass in the DOM: Security componentEPSS 0.5%CVE-2026-74979CRITICALMitigation bypass in the Add-ons Manager componentEPSS 0.5%