Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2022-22757MEDIUMRemote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to thEPSS 0.2%CVE-2025-11711MEDIUMSome non-writable Object properties could be modifiedEPSS 0.2%CVE-2026-2790HIGHSame-origin policy bypass in the Networking: JAR componentEPSS 0.2%CVE-2024-3861MEDIUMIf an AlignedBuffer were assigned to itself, the subsequent self-move could result in an incorrect reference count and later use-after-free.EPSS 0.2%CVE-2019-11753—The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unpriviEPSS 0.2%CVE-2025-6428MEDIUMFirefox for Android opened URLs specified in a link querystring parameterEPSS 0.2%CVE-2026-12325MEDIUMDenial-of-service in the Graphics: ImageLib componentEPSS 0.2%CVE-2026-6777MEDIUMOther issue in the Networking: DNS componentEPSS 0.2%CVE-2025-5020MEDIUMLinks using non-HTTP schemes opened from other apps such as Safari could have allowed spoofing of website addressesEPSS 0.2%CVE-2025-54144MEDIUMInternal Firefox open-text URL scheme allowed loading of arbitrary URLsEPSS 0.2%CVE-2025-0239MEDIUMAlt-Svc ALPN validation failure when redirectedEPSS 0.2%CVE-2026-92039MEDIUMMitigation bypass in the DOM: Notifications componentEPSS 0.2%CVE-2026-74962HIGHSite isolation issue in the Networking: Cookies componentEPSS 0.2%CVE-2026-74960HIGHSite isolation issue in the WebExtensions componentEPSS 0.2%CVE-2025-8364MEDIUMAddress bar spoofing using an blob URI on Firefox for AndroidEPSS 0.2%CVE-2025-55028MEDIUMJavaScript alerts could impede UI interaction or allow denial of service attacksEPSS 0.2%CVE-2026-12303MEDIUMInformation disclosure due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.2%CVE-2026-84120MEDIUMUse-after-free in the Audio/Video componentEPSS 0.2%CVE-2026-13356MEDIUMInterrupted navigation could allow address bar origin spoofing in Firefox for iOSEPSS 0.2%CVE-2024-4775MEDIUMAn iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and unEPSS 0.2%