Vulnerabilidades en mozilla

2105 resultados
Análisis Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2017-7798The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worsEPSS 2.1%CVE-2018-12391During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. BecausEPSS 2.1%CVE-2018-5163If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternatEPSS 2.1%CVE-2017-5448An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs withEPSS 2.1%CVE-2019-9796A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a EPSS 2.1%CVE-2018-5182If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specifEPSS 2.1%CVE-2018-12403If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. ThiEPSS 2.1%CVE-2018-5161Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 EPSS 2.1%CVE-2018-5113The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was noEPSS 2.0%CVE-2018-12374Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulEPSS 2.0%CVE-2016-9068A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects EPSS 2.0%CVE-2021-43537An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitablEPSS 2.0%CVE-2016-8635MEDIUMIt was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attackerEPSS 2.0%CVE-2022-28282MEDIUMBy using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript exEPSS 2.0%CVE-2017-7803When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorreEPSS 2.0%CVE-2017-7764Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of bEPSS 2.0%CVE-2017-7752A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are EPSS 2.0%CVE-2016-5289Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effoEPSS 2.0%CVE-2017-7806A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potenEPSS 2.0%CVE-2019-17016When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This EPSS 2.0%