Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2017-7798The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worsEPSS 2.1%CVE-2018-12391During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. BecausEPSS 2.1%CVE-2018-5163If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternatEPSS 2.1%CVE-2017-5448An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs withEPSS 2.1%CVE-2019-9796A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a EPSS 2.1%CVE-2018-5182If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specifEPSS 2.1%CVE-2018-12403If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. ThiEPSS 2.1%CVE-2018-5161Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 EPSS 2.1%CVE-2018-5113The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was noEPSS 2.0%CVE-2018-12374Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulEPSS 2.0%CVE-2016-9068A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects EPSS 2.0%CVE-2021-43537An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitablEPSS 2.0%CVE-2016-8635MEDIUMIt was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attackerEPSS 2.0%CVE-2022-28282MEDIUMBy using a link with <code>rel="localization"</code> a use-after-free could have been triggered by destroying an object during JavaScript exEPSS 2.0%CVE-2017-7803When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorreEPSS 2.0%CVE-2017-7764Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of bEPSS 2.0%CVE-2017-7752A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are EPSS 2.0%CVE-2016-5289Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effoEPSS 2.0%CVE-2017-7806A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potenEPSS 2.0%CVE-2019-17016When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This EPSS 2.0%