Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2026-18809MEDIUMInformation disclosure in Firefox for Android and Firefox Focus for AndroidEPSS 0.4%CVE-2025-13022CRITICALIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2022-29910MEDIUMWhen closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only afEPSS 0.4%CVE-2024-3853HIGHA use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerabEPSS 0.4%CVE-2026-6765MEDIUMInformation disclosure in the Form Autofill componentEPSS 0.4%CVE-2026-0881CRITICALSandbox escape in the Messaging System componentEPSS 0.4%CVE-2024-6605HIGHFirefox Android missed activation delay to prevent tapjackingEPSS 0.4%CVE-2025-13026CRITICALSandbox escape due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2025-6429MEDIUMIncorrect parsing of URLs could have allowed embedding of youtube.comEPSS 0.4%CVE-2025-13024CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2025-13023CRITICALSandbox escape due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2025-11719CRITICALUse-after-free caused by the native messaging web extension API on WindowsEPSS 0.4%CVE-2026-3889MEDIUMSpoofing issue in ThunderbirdEPSS 0.4%CVE-2025-10528HIGHSandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D componentEPSS 0.4%CVE-2020-15657—Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capableEPSS 0.4%CVE-2025-8035HIGHMemory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2026-0888MEDIUMInformation disclosure in the XML componentEPSS 0.4%CVE-2025-10534HIGHSpoofing issue in the Site Permissions componentEPSS 0.4%CVE-2026-4684HIGHRace condition, use-after-free in the Graphics: WebRender componentEPSS 0.4%CVE-2025-2830MEDIUMInformation Disclosure of /tmp directory listingEPSS 0.4%