Vulnerabilidades en Mozilla

2105 resultados
Análisis Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2021-29944—Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execuEPSS 0.7%CVE-2026-4686HIGHIncorrect boundary conditions in the Graphics: Canvas2D componentEPSS 0.7%CVE-2022-45421HIGHMozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed EPSS 0.7%CVE-2022-0566HIGHIt may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when procEPSS 0.7%CVE-2022-34476CRITICALASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulneraEPSS 0.7%CVE-2022-45408MEDIUMThrough a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification pEPSS 0.7%CVE-2024-2616LOWTo harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnEPSS 0.7%CVE-2024-11691HIGHCertain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in EPSS 0.7%CVE-2022-46877MEDIUMBy confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofiEPSS 0.7%CVE-2020-26962—Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have beEPSS 0.7%CVE-2011-2670—Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style SheetsEPSS 0.7%CVE-2022-28289HIGHMozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safetEPSS 0.7%CVE-2022-45403MEDIUMService Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media cEPSS 0.7%CVE-2023-29548MEDIUMA wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, FoEPSS 0.7%CVE-2022-36319HIGHWhen combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vuEPSS 0.7%CVE-2023-5723—An attacker with temporary script access to a site could have set a cookie containing invalid characters using `document.cookie` that could EPSS 0.7%CVE-2024-10463HIGHVideo frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, FirefEPSS 0.7%CVE-2022-38473HIGHA cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). ThisEPSS 0.7%CVE-2026-2762CRITICALInteger overflow in the JavaScript: Standard Library componentEPSS 0.7%CVE-2023-25751—Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could leaEPSS 0.7%