Vulnerabilidades en mozilla

2105 resultados
Análisis Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2026-16356CRITICALSandbox escape due to use-after-free in the Disability Access APIs componentEPSS 0.4%CVE-2026-16351CRITICALSandbox escape due to use-after-free in the DOM: Navigation componentEPSS 0.4%CVE-2022-38474MEDIUMA website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not alloEPSS 0.4%CVE-2026-16352CRITICALSandbox escape due to use-after-free in the Disability Access APIs componentEPSS 0.4%CVE-2025-54145CRITICALScanning a malicious URL utilizing Firefox's open-text scheme with the QR code scanner could load arbitrary websitesEPSS 0.4%CVE-2018-12379—When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading EPSS 0.4%CVE-2026-12295CRITICALSandbox escape in the DOM: Navigation componentEPSS 0.4%CVE-2026-12296CRITICALSandbox escape in the Security: Process Sandboxing componentEPSS 0.4%CVE-2024-4766MEDIUMDifferent techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusioEPSS 0.4%CVE-2026-12297CRITICALSandbox escape due to incorrect boundary conditions in the Networking componentEPSS 0.4%CVE-2024-11701MEDIUMThe incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusEPSS 0.4%CVE-2024-10468CRITICALPotential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability aEPSS 0.4%CVE-2026-8969HIGHMitigation bypass in the DOM: Security componentEPSS 0.4%CVE-2026-8964HIGHSpoofing issue in the Popup Blocker componentEPSS 0.4%CVE-2022-42930HIGHIf two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This EPSS 0.4%CVE-2024-6601MEDIUMRace condition in permission assignmentEPSS 0.4%CVE-2025-1014HIGHCertificate length was not properly checkedEPSS 0.4%CVE-2025-3032HIGHLeaking file descriptors from the fork serverEPSS 0.4%CVE-2024-8386MEDIUMIf a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform EPSS 0.4%CVE-2026-16368CRITICALIncorrect boundary conditions in the JavaScript: WebAssembly componentEPSS 0.4%