Vulnerabilidades en mozilla
2105 resultadosAnálisis Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2026-15718MEDIUMInvalid pointer in the JavaScript: WebAssembly componentEPSS 0.5%CVE-2025-5268HIGHMemory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11EPSS 0.5%CVE-2020-15671—When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the inputEPSS 0.5%CVE-2026-4692CRITICALSandbox escape in the Responsive Design Mode componentEPSS 0.5%CVE-2023-37456—The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS <EPSS 0.5%CVE-2024-3865HIGHMemory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2025-4093HIGHMemory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10EPSS 0.5%CVE-2026-74941HIGHPrivilege escalation in the Graphics: CanvasWebGL componentEPSS 0.5%CVE-2026-4691CRITICALUse-after-free in the CSS Parsing and Computation componentEPSS 0.5%CVE-2026-4696CRITICALUse-after-free in the Layout: Text and Fonts componentEPSS 0.5%CVE-2021-23980MEDIUMA mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags style, title, noscripEPSS 0.5%CVE-2026-2807CRITICALMemory safety bugs fixed in Firefox 148 and Thunderbird 148EPSS 0.5%CVE-2026-0891HIGHMemory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147EPSS 0.5%CVE-2025-54143CRITICALSandboxed iframes could allow local downloads despite sandbox restrictionsEPSS 0.5%CVE-2026-92053HIGHPrivilege escalation in the Graphics: CanvasWebGL componentEPSS 0.5%CVE-2026-0877HIGHMitigation bypass in the DOM: Security componentEPSS 0.5%CVE-2020-15682—When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An aEPSS 0.5%CVE-2026-92045CRITICALSandbox escape due to incorrect boundary conditions in the WebRTC componentEPSS 0.5%CVE-2026-92054HIGHPrivilege escalation in the Memory componentEPSS 0.5%CVE-2026-92071CRITICALSandbox escape due to incorrect boundary conditions in the Widget: Win32 componentEPSS 0.5%