Vulnerabilidades en mozilla

2105 resultados
Análisis Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2024-6605HIGHFirefox Android missed activation delay to prevent tapjackingEPSS 0.4%CVE-2025-6429MEDIUMIncorrect parsing of URLs could have allowed embedding of youtube.comEPSS 0.4%CVE-2025-13024CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2025-13026CRITICALSandbox escape due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-92075CRITICALMitigation bypass in the Networking componentEPSS 0.4%CVE-2026-3889MEDIUMSpoofing issue in ThunderbirdEPSS 0.4%CVE-2025-11719CRITICALUse-after-free caused by the native messaging web extension API on WindowsEPSS 0.4%CVE-2026-92041CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.4%CVE-2026-92038CRITICALMitigation bypass in the Remote Settings Client componentEPSS 0.4%CVE-2020-15657—Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capableEPSS 0.4%CVE-2025-10528HIGHSandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D componentEPSS 0.4%CVE-2026-0888MEDIUMInformation disclosure in the XML componentEPSS 0.4%CVE-2025-8035HIGHMemory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2025-10534HIGHSpoofing issue in the Site Permissions componentEPSS 0.4%CVE-2026-4684HIGHRace condition, use-after-free in the Graphics: WebRender componentEPSS 0.4%CVE-2025-2830MEDIUMInformation Disclosure of /tmp directory listingEPSS 0.4%CVE-2025-6432HIGHDNS Requests leaked outside of a configured SOCKS proxyEPSS 0.4%CVE-2026-92006HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.4%CVE-2026-92018CRITICALSandbox escape in the DOM: Core & HTML componentEPSS 0.4%CVE-2025-26696HIGHCrafted email message incorrectly shown as being encryptedEPSS 0.3%