Vulnerabilidades en mozilla

2105 resultados
Análisis Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2026-6756HIGHMitigation bypass in Firefox for AndroidEPSS 0.4%CVE-2026-16377CRITICALMitigation bypass in the PDF Viewer componentEPSS 0.4%CVE-2024-1563HIGHAn attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom FEPSS 0.4%CVE-2024-0605HIGHUsing a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bEPSS 0.4%CVE-2026-16383CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.4%CVE-2026-4712HIGHInformation disclosure in the Widget: Cocoa componentEPSS 0.4%CVE-2024-2608HIGH`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows,EPSS 0.4%CVE-2023-25749MEDIUMAndroid applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities. FEPSS 0.4%CVE-2023-6870—Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *ThisEPSS 0.4%CVE-2026-12291HIGHUse-after-free in the Networking: HTTP componentEPSS 0.4%CVE-2017-7766—An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla MaEPSS 0.4%CVE-2024-1554CRITICALThe `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contEPSS 0.4%CVE-2024-5698MEDIUMBy manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This coulEPSS 0.4%CVE-2025-8043CRITICALIncorrect URL truncationEPSS 0.4%CVE-2024-31392HIGHIf an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status ThiEPSS 0.4%CVE-2026-74978HIGHClickjacking issue in the Widget componentEPSS 0.4%CVE-2024-7530CRITICALIncorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.EPSS 0.4%CVE-2026-6767MEDIUMOther issue in the Libraries component in NSSEPSS 0.4%CVE-2024-10004CRITICALOpening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in tEPSS 0.4%CVE-2026-92005MEDIUMUse-after-free in the Audio/Video: Web Codecs componentEPSS 0.4%