Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2022-34469HIGHWhen a TLS Certificate error occurs on a domain protected by the HSTS header, the browser should not allow the user to bypass the certificatEPSS 0.4%CVE-2026-7324HIGHMemory safety bugs fixed in Thunderbird 150.0.1EPSS 0.4%CVE-2025-11721CRITICALMemory safety bug fixed in Firefox 144 and Thunderbird 144EPSS 0.4%CVE-2024-3862MEDIUMThe MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. ThEPSS 0.4%CVE-2022-38472MEDIUMAn attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the adEPSS 0.4%CVE-2023-2142MEDIUMNunjucks autoescape bypass leads to cross site scriptingEPSS 0.4%CVE-2026-12326HIGHMemory safety bugs fixed in Firefox 152 and Thunderbird 152EPSS 0.4%CVE-2026-12294CRITICALSandbox escape in the DOM: Workers componentEPSS 0.4%CVE-2017-5409—The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callbaEPSS 0.4%CVE-2026-16392CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2026-16376HIGHDenial-of-service in the Graphics: WebGPU componentEPSS 0.4%CVE-2024-8388MEDIUMMultiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullEPSS 0.4%CVE-2025-1019MEDIUMFullscreen notification not properly displayedEPSS 0.4%CVE-2025-9181MEDIUMUninitialized memory in the JavaScript Engine componentEPSS 0.4%CVE-2025-11713HIGHPotential user-assisted code execution in “Copy as cURL” commandEPSS 0.4%CVE-2022-22758HIGHWhen clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phoEPSS 0.4%CVE-2023-1521HIGHLocal Privilege Escalation in sccacheEPSS 0.4%CVE-2025-13021CRITICALIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2018-12385—A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profileEPSS 0.4%CVE-2025-1941CRITICALLock screen setting bypass in Firefox Focus for AndroidEPSS 0.4%