Vulnerabilidades en Mozilla

2105 resultados
Análisis Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2025-1011CRITICALA bug in WebAssembly code generation could result in a crashEPSS 0.6%CVE-2023-50761—The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, ThunderbirEPSS 0.6%CVE-2023-50762—When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This isEPSS 0.6%CVE-2026-4705CRITICALUndefined behavior in the WebRTC: Signaling componentEPSS 0.6%CVE-2023-4573—Memory corruption in IPC CanvasTranslatorEPSS 0.6%CVE-2023-4047—A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vEPSS 0.6%CVE-2023-32205—In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusionEPSS 0.6%CVE-2026-84141CRITICALInteger overflow in the Graphics: ImageLib componentEPSS 0.6%CVE-2022-22747MEDIUMAfter accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This EPSS 0.6%CVE-2024-7519HIGHInsufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to peEPSS 0.6%CVE-2026-92240CRITICALOut-of-bounds read in IMAP response parserEPSS 0.6%CVE-2022-40961MEDIUMDuring startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>EPSS 0.6%CVE-2026-8094CRITICALOther issue in the WebRTC componentEPSS 0.6%CVE-2024-3852HIGHGetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, FireEPSS 0.6%CVE-2022-22753HIGHA Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrarEPSS 0.6%CVE-2022-45407HIGHIf an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentEPSS 0.6%CVE-2026-4704HIGHDenial-of-service in the WebRTC: Signaling componentEPSS 0.6%CVE-2026-84637CRITICALCalendar invitation attachments could launch local executablesEPSS 0.6%CVE-2019-11754—When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious websiEPSS 0.6%CVE-2023-28161HIGHIf temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permisEPSS 0.6%