Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2019-9804In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause theEPSS 1.8%CVE-2019-9815If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.EPSS 1.8%CVE-2018-12364NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 rEPSS 1.8%CVE-2018-5173The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This cEPSS 1.8%CVE-2018-5128A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in EPSS 1.8%CVE-2018-5092A use-after-free vulnerability can occur when the thread for a Web Worker is freed from memory prematurely instead of from memory in the maiEPSS 1.8%CVE-2019-11727A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures whenEPSS 1.8%CVE-2019-17015During the initialization of a new content process, a pointer offset can be manipulated leading to memory corruption and a potentially exploEPSS 1.8%CVE-2017-7829It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's addressEPSS 1.8%CVE-2019-11759An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an atEPSS 1.8%CVE-2019-11743Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload evenEPSS 1.8%CVE-2018-5101A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crEPSS 1.8%CVE-2017-5416In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. EPSS 1.8%CVE-2017-5406A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and emptEPSS 1.8%CVE-2017-7789If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict TranEPSS 1.8%CVE-2016-9076An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack reEPSS 1.8%CVE-2016-5288Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pageEPSS 1.8%CVE-2018-5184Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and ThEPSS 1.8%CVE-2019-9794A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handlerEPSS 1.8%CVE-2017-5374Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough efEPSS 1.8%