Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2019-17016When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This EPSS 2.0%CVE-2018-5112Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but thisEPSS 2.0%CVE-2018-12367In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure preEPSS 2.0%CVE-2017-7846It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website"EPSS 2.0%CVE-2017-5425The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access tEPSS 2.0%CVE-2020-15673Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corrEPSS 2.0%CVE-2016-9896Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability aEPSS 2.0%CVE-2018-18508In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulEPSS 2.0%CVE-2018-5162Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52EPSS 2.0%CVE-2017-7821A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered withoutEPSS 2.0%CVE-2020-12422In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out oEPSS 1.9%CVE-2018-18495WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. TEPSS 1.9%CVE-2017-5421A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what siteEPSS 1.9%CVE-2017-7762When entered directly, Reader Mode did not strip the username and password section of URLs displayed in the addressbar. This can be used forEPSS 1.9%CVE-2016-9070A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScripEPSS 1.9%CVE-2019-17005The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the EPSS 1.9%CVE-2025-2857CRITICALIncorrect handle could lead to sandbox escapesEPSS 1.9%CVE-2017-7780Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume that with enough effoEPSS 1.9%CVE-2020-15678When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This EPSS 1.9%CVE-2016-9071Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a uEPSS 1.9%