Vulnerabilidades en mozilla
2105 resultadosAnálisis Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2019-9804—In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause theEPSS 1.8%CVE-2019-9815—If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.EPSS 1.8%CVE-2018-12364—NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 rEPSS 1.8%CVE-2018-5173—The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This cEPSS 1.8%CVE-2018-5128—A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in EPSS 1.8%CVE-2018-5092—A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the maiEPSS 1.8%CVE-2019-11727—A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures whenEPSS 1.8%CVE-2019-17015—During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploEPSS 1.8%CVE-2017-7829—It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's addressEPSS 1.8%CVE-2019-11759—An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an atEPSS 1.8%CVE-2019-11743—Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload evenEPSS 1.8%CVE-2018-5101—A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crEPSS 1.8%CVE-2017-5416—In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. EPSS 1.8%CVE-2017-5406—A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and emptEPSS 1.8%CVE-2017-7789—If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict TranEPSS 1.8%CVE-2016-9076—An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack reEPSS 1.8%CVE-2016-5288—Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pageEPSS 1.8%CVE-2018-5184—Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and ThEPSS 1.8%CVE-2019-9794—A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handlerEPSS 1.8%CVE-2017-5374—Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough efEPSS 1.8%