Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2026-92038CRITICALMitigation bypass in the Remote Settings Client componentEPSS 0.5%CVE-2026-92079CRITICALMitigation bypass in the Widget: Win32 componentEPSS 0.5%CVE-2024-9399HIGHA website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service conEPSS 0.5%CVE-2025-3030HIGHMemory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9EPSS 0.5%CVE-2023-6211—If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked EPSS 0.5%CVE-2026-16411CRITICALMemory safety bugs fixed in Firefox 153EPSS 0.5%CVE-2026-12292HIGHIncorrect boundary conditions in the Web Audio componentEPSS 0.5%CVE-2022-26382MEDIUMWhile the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel atEPSS 0.5%CVE-2023-6871—Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability EPSS 0.5%CVE-2023-6868—In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined oneEPSS 0.5%CVE-2023-23600—Notification permissions persisted between Normal and Private Browsing on AndroidEPSS 0.5%CVE-2023-29546MEDIUMWhen recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leakingEPSS 0.5%CVE-2024-4767MEDIUMIf the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. ThisEPSS 0.5%CVE-2026-74946HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.5%CVE-2023-0616MEDIUMIf a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, EPSS 0.5%CVE-2024-8389CRITICALMemory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2025-5268HIGHMemory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11EPSS 0.5%CVE-2024-11694MEDIUMEnhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeEPSS 0.5%CVE-2026-15718MEDIUMInvalid pointer in the JavaScript: WebAssembly componentEPSS 0.5%CVE-2024-7524MEDIUMFirefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by ContEPSS 0.5%