Vulnerabilities in mozilla
2,105 resultsVexday analysis
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2021-29948—Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local procesEPSS 0.3%CVE-2025-13020HIGHUse-after-free in the WebRTC: Audio/Video componentEPSS 0.3%CVE-2025-5270HIGHSNI was sometimes unencryptedEPSS 0.3%CVE-2026-84140CRITICALSite isolation issue in the DOM: Navigation componentEPSS 0.3%CVE-2025-3035MEDIUMTab title disclosure across pages when using AI chatbotEPSS 0.3%CVE-2024-53975MEDIUMAccessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appeEPSS 0.3%CVE-2025-0510MEDIUMAddress of e-mail sender can be spoofed by malicious emailEPSS 0.3%CVE-2023-37210—A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoEPSS 0.3%CVE-2025-6434MEDIUMHTTPS-Only exception screen lacked anti-clickjacking delayEPSS 0.3%CVE-2024-0606MEDIUMAn attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to uEPSS 0.3%CVE-2026-6757MEDIUMInvalid pointer in the JavaScript: WebAssembly componentEPSS 0.3%CVE-2017-7767—The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla WindowsEPSS 0.3%CVE-2026-6762MEDIUMSpoofing issue in the DOM: Core & HTML componentEPSS 0.3%CVE-2024-9391MEDIUMA user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may EPSS 0.3%CVE-2017-7796—On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write a new log of that nEPSS 0.3%CVE-2026-16407CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.3%CVE-2026-16379HIGHPrivilege escalation in the DOM: Content Processes componentEPSS 0.3%CVE-2026-74984MEDIUMRace condition in the JavaScript Engine componentEPSS 0.3%CVE-2024-26283HIGHAn attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom FEPSS 0.3%CVE-2026-16365HIGHPrivilege escalation in the DOM: Workers componentEPSS 0.3%