Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2026-16350CRITICALIncorrect boundary conditions in the Audio/Video: cubeb componentEPSS 0.4%CVE-2025-8034HIGHMemory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2026-8963HIGHSpoofing issue in the Web Speech componentEPSS 0.4%CVE-2026-8960HIGHSpoofing issue in WebExtensionsEPSS 0.4%CVE-2025-14329HIGHPrivilege escalation in the Netmonitor componentEPSS 0.4%CVE-2025-14328HIGHPrivilege escalation in the Netmonitor componentEPSS 0.4%CVE-2026-8952HIGHPrivilege escalation in the Application Update componentEPSS 0.4%CVE-2017-5387—The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on aEPSS 0.4%CVE-2026-6770MEDIUMOther issue in the Storage: IndexedDB componentEPSS 0.4%CVE-2026-8962HIGHMitigation bypass in the DOM: Security componentEPSS 0.4%CVE-2023-29538—Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> UREPSS 0.4%CVE-2016-9062—Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" files within the FirEPSS 0.4%CVE-2024-6606HIGHOut-of-bounds read in clipboard componentEPSS 0.4%CVE-2026-8945HIGHSandbox escape in Firefox and Firefox Focus for AndroidEPSS 0.4%CVE-2026-4711CRITICALUse-after-free in the Widget: Cocoa componentEPSS 0.4%CVE-2024-5689MEDIUMIn addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and dEPSS 0.4%CVE-2024-3855MEDIUMIn certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 12EPSS 0.4%CVE-2024-6600MEDIUMMemory corruption in WebGL APIEPSS 0.4%CVE-2026-12290HIGHMemory safety bug fixed in Firefox 152EPSS 0.4%CVE-2019-9808—If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originatEPSS 0.4%