Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2016-9067Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.EPSS 1.9%CVE-2019-17008When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vuEPSS 1.9%CVE-2020-26971Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulneraEPSS 1.9%CVE-2018-18511Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *NoteEPSS 1.9%CVE-2017-5413A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.EPSS 1.9%CVE-2020-6814Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruptEPSS 1.9%CVE-2019-17021During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses fromEPSS 1.9%CVE-2016-9078Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can EPSS 1.9%CVE-2020-12420When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and EPSS 1.9%CVE-2019-9790A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then EPSS 1.9%CVE-2021-29951The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access EPSS 1.9%CVE-2018-12375Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that with enough effort thaEPSS 1.8%CVE-2018-5174In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files andEPSS 1.8%CVE-2017-5471Memory safety bugs were reported in Firefox 53. Some of these bugs showed evidence of memory corruption and we presume that with enough effoEPSS 1.8%CVE-2020-12421When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by EPSS 1.8%CVE-2018-12381Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are EPSS 1.8%CVE-2016-9895Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vuEPSS 1.8%CVE-2016-9065The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake EPSS 1.8%CVE-2017-5450A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorreEPSS 1.8%CVE-2017-7791On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following paEPSS 1.8%