Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2025-1942CRITICALDisclosure of uninitialized memory when .toUpperCase() causes string to get longerEPSS 0.5%CVE-2021-43529CRITICALThunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages. ThundeEPSS 0.5%CVE-2026-2795HIGHUse-after-free in the JavaScript: GC componentEPSS 0.5%CVE-2026-16360CRITICALMemory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153EPSS 0.5%CVE-2026-92044HIGHInformation disclosure in the Networking: HTTP componentEPSS 0.5%CVE-2024-11706MEDIUMA null pointer dereference may have inadvertently occurred in `pk12util`, and specifically in the `SEC_ASN1DecodeItem_Util` function, when hEPSS 0.5%CVE-2022-36317MEDIUMWhen visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanEPSS 0.5%CVE-2026-0883MEDIUMInformation disclosure in the Networking componentEPSS 0.5%CVE-2026-2634CRITICALSpoofed web content presented under trusted domains using scripted navigation on Firefox iOSEPSS 0.5%CVE-2026-74949HIGHPrivilege escalation due to use-after-free in the Graphics: Canvas2D componentEPSS 0.5%CVE-2026-2785HIGHInvalid pointer in the JavaScript Engine componentEPSS 0.5%CVE-2026-92060HIGHUse-after-free in the Internationalization componentEPSS 0.5%CVE-2026-92046HIGHUse-after-free in the Graphics componentEPSS 0.5%CVE-2026-92058HIGHUse-after-free in the Graphics componentEPSS 0.5%CVE-2025-8031CRITICALIncorrect URL stripping in CSP reportsEPSS 0.5%CVE-2026-92049HIGHUse-after-free in the Widget: Win32 componentEPSS 0.5%CVE-2026-92056HIGHUse-after-free in the Graphics: Text componentEPSS 0.5%CVE-2026-92067HIGHUse-after-free in the Widget: Gtk componentEPSS 0.5%CVE-2025-1010CRITICALUse-after-free in Custom HighlightEPSS 0.5%CVE-2026-8388MEDIUMIncorrect boundary conditions in the JavaScript Engine: JIT componentEPSS 0.5%