Vulnerabilidades en mozilla
2105 resultadosAnálisis Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2026-12326HIGHMemory safety bugs fixed in Firefox 152 and Thunderbird 152EPSS 0.4%CVE-2026-12294CRITICALSandbox escape in the DOM: Workers componentEPSS 0.4%CVE-2023-1521HIGHLocal Privilege Escalation in sccacheEPSS 0.4%CVE-2026-16376HIGHDenial-of-service in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-16392CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2024-8388MEDIUMMultiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullEPSS 0.4%CVE-2025-1019MEDIUMFullscreen notification not properly displayedEPSS 0.4%CVE-2017-5409—The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callbaEPSS 0.4%CVE-2022-22758HIGHWhen clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phoEPSS 0.4%CVE-2025-9181MEDIUMUninitialized memory in the JavaScript Engine componentEPSS 0.4%CVE-2025-11713HIGHPotential user-assisted code execution in “Copy as cURL” commandEPSS 0.4%CVE-2025-13021CRITICALIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-18809MEDIUMInformation disclosure in Firefox for Android and Firefox Focus for AndroidEPSS 0.4%CVE-2018-12385—A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profileEPSS 0.4%CVE-2025-13022CRITICALIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2022-29910MEDIUMWhen closed or sent to the background, Firefox for Android would not properly record and persist HSTS settings.<br>*Note: This issue only afEPSS 0.4%CVE-2024-3853HIGHA use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerabEPSS 0.4%CVE-2026-0881CRITICALSandbox escape in the Messaging System componentEPSS 0.4%CVE-2026-6765MEDIUMInformation disclosure in the Form Autofill componentEPSS 0.4%CVE-2025-13023CRITICALSandbox escape due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%