Vulnerabilidades en mozilla
2105 resultadosAnálisis Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2026-84136CRITICALOther issue in the DOM: Navigation componentEPSS 0.4%CVE-2026-6783MEDIUMIncorrect boundary conditions, integer overflow in the Audio/Video: Playback componentEPSS 0.4%CVE-2022-1834MEDIUMWhen displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird EPSS 0.4%CVE-2025-3875HIGHSender Spoofing via Malformed From Header in ThunderbirdEPSS 0.4%CVE-2025-8033MEDIUMIncorrect JavaScript state machine for generatorsEPSS 0.4%CVE-2025-8027MEDIUMJavaScript engine only wrote partial return value to stackEPSS 0.4%CVE-2025-14327HIGHSpoofing issue in the Downloads Panel componentEPSS 0.4%CVE-2026-84143CRITICALInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15EPSS 0.4%CVE-2026-16382CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.4%CVE-2024-6608MEDIUMCursor could be moved out of the viewport using pointerlock.EPSS 0.4%CVE-2025-9182HIGHDenial-of-service due to out-of-memory in the Graphics: WebRender componentEPSS 0.4%CVE-2026-16367CRITICALSandbox escape due to invalid pointer in the Disability Access APIs componentEPSS 0.4%CVE-2026-16388CRITICALSandbox escape in the DOM: Networking componentEPSS 0.4%CVE-2026-3847HIGHMemory safety bugs fixed in Firefox 148.0.2EPSS 0.4%CVE-2026-12305HIGHMemory safety bug fixed in Firefox 152EPSS 0.4%CVE-2022-34473MEDIUMThe HTML Sanitizer should have sanitized the <code>href</code> attribute of SVG <code><use></code> tags; however it incorrectly did noEPSS 0.4%CVE-2022-1197MEDIUMWhen importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the keyEPSS 0.4%CVE-2024-9397MEDIUMA missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjackingEPSS 0.4%CVE-2023-0430MEDIUMCertificate OCSP revocation status was not checked when verifying S/Mime signatures. Mail signed with a revoked certificate would be displayEPSS 0.4%CVE-2024-4774MEDIUMThe `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data memEPSS 0.4%