Vulnerabilidades en mozilla

2105 resultados
Análisis Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2026-84144HIGHInternally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2EPSS 0.4%CVE-2026-8965HIGHInformation disclosure in the DOM: Security componentEPSS 0.4%CVE-2026-74976MEDIUMJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2026-4721CRITICALMemory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149EPSS 0.4%CVE-2025-8036HIGHDNS rebinding circumvents CORSEPSS 0.4%CVE-2026-4720CRITICALMemory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149EPSS 0.4%CVE-2018-5105—WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file runnEPSS 0.4%CVE-2025-1932HIGHInconsistent comparator in XSLT sorting led to out-of-bounds accessEPSS 0.4%CVE-2022-38475MEDIUMAn attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the valueEPSS 0.4%CVE-2021-23993—An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpeEPSS 0.4%CVE-2025-11710CRITICALCross-process information leaked due to malicious IPC messagesEPSS 0.4%CVE-2023-4580—Push notifications saved to disk unencryptedEPSS 0.4%CVE-2025-11709CRITICALOut of bounds read/write in a privileged process triggered by WebGL texturesEPSS 0.4%CVE-2026-8093HIGHMemory safety bugs fixed in Firefox 150.0.2EPSS 0.4%CVE-2024-0752MEDIUMA use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted iEPSS 0.4%CVE-2016-5294—The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulEPSS 0.4%CVE-2022-22749MEDIUMWhen scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.<br>*This bug only aEPSS 0.4%CVE-2026-84642HIGHAllowed UNC hostnames for attachments interpreted as a regular expressionEPSS 0.4%CVE-2026-4717CRITICALPrivilege escalation in the Netmonitor componentEPSS 0.4%CVE-2024-4776HIGHA file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126EPSS 0.4%