Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-16396HIGHPrivilege escalation in WebExtensionsEPSS 0.2%CVE-2026-92055HIGHPrivilege escalation in the DevTools componentEPSS 0.2%CVE-2017-5427—A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user wiEPSS 0.2%CVE-2025-23108MEDIUMFirefox Mobile iOS Full Address Bar Spoof Using Open in New Tab and Javascript URIEPSS 0.2%CVE-2026-92062HIGHPrivilege escalation in the Session Restore componentEPSS 0.2%CVE-2026-92042HIGHRace condition in the DOM: Content Processes componentEPSS 0.2%CVE-2026-92047HIGHPrivilege escalation in the Crash Reporting componentEPSS 0.2%CVE-2026-92073HIGHPrivilege escalation in the Enterprise Policies componentEPSS 0.2%CVE-2026-12309MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.2%CVE-2026-92072HIGHIncorrect boundary conditions in the Safe Browsing componentEPSS 0.2%CVE-2025-27426MEDIUMFirefox Mobile iOS Full Address Bar Spoof Using Server-Side Redirect to internal error pageEPSS 0.2%CVE-2025-11716MEDIUMSandboxed iframes allowed links to open in external apps (Android only)EPSS 0.2%CVE-2025-8037CRITICALNameless cookies shadow secure cookiesEPSS 0.2%CVE-2025-13012HIGHRace condition in the Graphics componentEPSS 0.2%CVE-2022-45415HIGHWhen downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the fEPSS 0.2%CVE-2023-37208—When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < EPSS 0.2%CVE-2026-8706MEDIUMSensitive user data could be leaked to other applications through Reader modeEPSS 0.2%CVE-2025-11153HIGHJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.2%CVE-2025-27425MEDIUMQR code user confirmation bypass with invalid protocolEPSS 0.2%CVE-2026-92078MEDIUMDenial-of-service in the Security componentEPSS 0.2%