Vulnerabilidades en mozilla
2105 resultadosAnálisis Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2024-4764CRITICALMultiple WebRTC threads could have claimed a newly connected audio input leading to use-after-free. This vulnerability affects Firefox < 126EPSS 0.6%CVE-2026-84134CRITICALOther issue in the Profile Backup componentEPSS 0.6%CVE-2026-74989CRITICALInternally found bugs fixed in Thunderbird 154EPSS 0.6%CVE-2021-24001—A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructuEPSS 0.6%CVE-2022-45420MEDIUMUse tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resultingEPSS 0.6%CVE-2023-29533—A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>winEPSS 0.6%CVE-2025-9179CRITICALSandbox escape due to invalid pointer in the Audio/Video: GMP componentEPSS 0.6%CVE-2026-2768CRITICALSandbox escape in the Storage: IndexedDB componentEPSS 0.6%CVE-2026-2777CRITICALPrivilege escalation in the Messaging System componentEPSS 0.6%CVE-2022-46883HIGHMozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in FirEPSS 0.6%CVE-2024-3858HIGHIt was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.EPSS 0.6%CVE-2021-23959—An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This iEPSS 0.6%CVE-2024-9398MEDIUMBy checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application whiEPSS 0.6%CVE-2026-2775CRITICALMitigation bypass in the DOM: HTML Parser componentEPSS 0.6%CVE-2026-92051CRITICALSpoofing issue due to invalid pointer in the Graphics componentEPSS 0.6%CVE-2024-10461MEDIUMIn multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a downlEPSS 0.6%CVE-2025-14324CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-16389CRITICALIncorrect boundary conditions, integer overflow in the Libraries component in NSSEPSS 0.6%CVE-2023-6206—The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possibleEPSS 0.6%CVE-2024-6607HIGHLeaving pointerlock by pressing the escape key could be preventedEPSS 0.6%