Vulnerabilidades en mozilla

2105 resultados
Análisis Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2021-4128MEDIUMWhen transitioning in and out of fullscreen mode, a graphics object was not correctly protected; resulting in memory corruption and a potentEPSS 0.5%CVE-2022-28284HIGHSVG's <code>&lt;use&gt;</code> element could have been used to load unexpected content that could have executed script in certain circumstanEPSS 0.5%CVE-2022-34480HIGHWithin the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freeEPSS 0.5%CVE-2023-25730MEDIUMA background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode iEPSS 0.5%CVE-2019-11737—If a wildcard ('*') is specified for the host in Content Security Policy (CSP) directives, any port or path restriction of the directive wilEPSS 0.5%CVE-2023-28177HIGHMemory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2021-43533—When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies tEPSS 0.5%CVE-2026-8092HIGHMemory safety bugs fixed in Firefox ESR 115.35.2, Firefox ESR 140.10.2 and Firefox 150.0.2EPSS 0.5%CVE-2024-4773HIGHWhen a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been useEPSS 0.5%CVE-2025-1020CRITICALMemory safety bugs fixed in Firefox 135 and Thunderbird 135EPSS 0.5%CVE-2024-6604HIGHMemory safety bugs fixed in Firefox 128, Firefox ESR 115.13, Thunderbird 128, and Thunderbird 115.13EPSS 0.5%CVE-2024-4768MEDIUMA bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulneEPSS 0.5%CVE-2026-4687CRITICALSandbox escape due to incorrect boundary conditions in the Telemetry componentEPSS 0.5%CVE-2026-92238CRITICALAmbiguous parsing of mail headersEPSS 0.5%CVE-2023-32210—Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. InEPSS 0.5%CVE-2026-2791CRITICALMitigation bypass in the Networking: Cache componentEPSS 0.5%CVE-2026-2784CRITICALMitigation bypass in the DOM: Security componentEPSS 0.5%CVE-2024-6603HIGHMemory corruption in thread creationEPSS 0.5%CVE-2026-2801HIGHIncorrect boundary conditions in the JavaScript: WebAssembly componentEPSS 0.5%CVE-2024-4777HIGHMemory safety bugs present in Firefox 125, Firefox ESR 115.10, and Thunderbird 115.10. Some of these bugs showed evidence of memory corruptiEPSS 0.5%