Vulnerabilidades en Mozilla

2105 resultados
Análisis Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2018-18492—A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options colEPSS 9.6%CVE-2018-12387—A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer beiEPSS 9.6%CVE-2025-4918CRITICALOut-of-bounds access when resolving Promise objectsEPSS 9.4%CVE-2025-0247CRITICALMemory safety bugs fixed in Firefox 134 and Thunderbird 134EPSS 9.3%CVE-2025-4919HIGHOut-of-bounds access when optimizing linear sumsEPSS 8.6%CVE-2018-5127—A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash.EPSS 7.9%CVE-2024-8897MEDIUMUnder certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be EPSS 7.6%CVE-2019-9813—Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read anEPSS 7.4%CVE-2017-7828—A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in useEPSS 7.3%CVE-2018-5097—A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by scriptEPSS 7.2%CVE-2018-5104—A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentiaEPSS 7.2%CVE-2018-5102—A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crEPSS 7.1%CVE-2020-6820HIGHUnder certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in tEPSS 7.1%KEVCVE-2017-5444—A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted dEPSS 6.9%CVE-2025-0244MEDIUMAddress bar spoofing using an invalid protocol scheme on Firefox for AndroidEPSS 6.5%CVE-2019-9816—A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypasEPSS 6.2%CVE-2020-6831—A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially EPSS 5.8%CVE-2016-9063—An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.EPSS 5.5%CVE-2018-5100—A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scrEPSS 5.4%CVE-2017-7778—A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use EPSS 5.1%