Vulnerabilities in mozilla

2,105 results
Vexday analysis

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2025-55029HIGHMalicious scripts could spam popups for denial of service attacksEPSS 0.3%CVE-2024-26282HIGHUsing an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affEPSS 0.3%CVE-2025-1935MEDIUMClickjacking the registerProtocolHandler info-barEPSS 0.3%CVE-2026-16402CRITICALInteger overflow in the Graphics: ImageLib componentEPSS 0.3%CVE-2026-4728MEDIUMSpoofing issue in the Privacy: Anti-Tracking componentEPSS 0.3%CVE-2016-5293—When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitraEPSS 0.3%CVE-2024-0749MEDIUMA phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerabEPSS 0.3%CVE-2026-16395CRITICALInteger overflow in the Audio/Video componentEPSS 0.3%CVE-2017-7836—The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. TEPSS 0.3%CVE-2026-84131HIGHPrivilege escalation due to invalid pointer in the Graphics componentEPSS 0.3%CVE-2025-11714HIGHMemory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2023-4104MEDIUMAn invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitraEPSS 0.3%CVE-2021-29963—Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for AndrEPSS 0.3%CVE-2026-92026HIGHUse-after-free in the Networking componentEPSS 0.3%CVE-2019-17009—When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to loEPSS 0.3%CVE-2026-92016HIGHUse-after-free in the Disability Access APIs componentEPSS 0.3%CVE-2025-13027HIGHMemory safety bugs fixed in Firefox 145 and Thunderbird 145EPSS 0.3%CVE-2017-5414—The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead EPSS 0.3%CVE-2025-1938MEDIUMMemory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8EPSS 0.3%CVE-2026-0887MEDIUMClickjacking issue, information disclosure in the PDF Viewer componentEPSS 0.3%