Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2022-26485HIGHRemoving an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abEPSS 14.3%KEVCVE-2017-5465An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible meEPSS 13.3%CVE-2019-9792The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magEPSS 13.2%CVE-2025-0242MEDIUMMemory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6EPSS 13.1%CVE-2017-5404A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside ofEPSS 12.7%CVE-2017-5415An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion EPSS 12.7%CVE-2023-4050In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable EPSS 12.6%CVE-2018-12386A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remEPSS 12.4%CVE-2017-5447An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could alEPSS 12.4%CVE-2018-5158The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafteEPSS 12.3%CVE-2018-5146An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects FirefoEPSS 11.4%CVE-2019-11703A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in parser_get_next_char when processing certain email messages,EPSS 10.5%CVE-2019-11704A flaw in Thunderbird's implementation of iCal causes a heap buffer overflow in icalmemory_strdup_and_dequote when processing certain email EPSS 10.5%CVE-2017-7783If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resultinEPSS 10.3%CVE-2019-11705A flaw in Thunderbird's implementation of iCal causes a stack buffer overflow in icalrecur_add_bydayrules when processing certain email messEPSS 9.9%CVE-2019-11706A flaw in Thunderbird's implementation of iCal causes a type confusion in icaltimezone_get_vtimezone_properties when processing certain emaiEPSS 9.7%CVE-2025-4918CRITICALOut-of-bounds access when resolving Promise objectsEPSS 9.4%CVE-2025-0247CRITICALMemory safety bugs fixed in Firefox 134 and Thunderbird 134EPSS 9.3%CVE-2018-18492A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options colEPSS 9.0%CVE-2016-9066A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data.EPSS 8.9%