Vulnerabilidades en mozilla

2105 resultados
Análisis Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2026-6784HIGHMemory safety bugs fixed in Firefox 150 and Thunderbird 150EPSS 0.4%CVE-2025-1018HIGHFullscreen notification is not displayed when fullscreen is re-requestedEPSS 0.4%CVE-2026-8957HIGHPrivilege escalation in the Enterprise Policies componentEPSS 0.4%CVE-2026-8970HIGHPrivilege escalation in the Security componentEPSS 0.4%CVE-2025-14323HIGHPrivilege escalation in the DOM: Notifications componentEPSS 0.4%CVE-2026-74950HIGHPrivilege escalation in the Downloads API componentEPSS 0.4%CVE-2026-6769HIGHPrivilege escalation in the Debugger componentEPSS 0.4%CVE-2026-6761HIGHPrivilege escalation in the Networking componentEPSS 0.4%CVE-2026-8955HIGHPrivilege escalation in the DOM: Workers componentEPSS 0.4%CVE-2026-74955HIGHPrivilege escalation in the Request Handling componentEPSS 0.4%CVE-2026-74952HIGHPrivilege escalation in the Application Update componentEPSS 0.4%CVE-2025-55031CRITICALPasskey phishing within Bluetooth rangeEPSS 0.4%CVE-2022-42927HIGHA same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.EPSS 0.4%CVE-2020-12423—When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, EPSS 0.4%CVE-2023-34415—When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that docuEPSS 0.4%CVE-2022-31746MEDIUMInternal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability aEPSS 0.4%CVE-2024-5687MEDIUMIf a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been inEPSS 0.4%CVE-2019-17003MEDIUMScanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.EPSS 0.4%CVE-2026-0885MEDIUMUse-after-free in the JavaScript: GC componentEPSS 0.4%CVE-2021-4221MEDIUMIf a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confuEPSS 0.4%