Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2018-5121Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an InteEPSS 1.5%CVE-2017-7838Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punyEPSS 1.5%CVE-2017-5463Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the conEPSS 1.5%CVE-2017-7837SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox <EPSS 1.5%CVE-2017-7823The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allowEPSS 1.5%CVE-2018-5132The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allEPSS 1.5%CVE-2021-38498During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potEPSS 1.5%CVE-2020-6829When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about theEPSS 1.5%CVE-2023-5730Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruptionEPSS 1.5%CVE-2021-38506Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to EPSS 1.5%CVE-2018-5175A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target EPSS 1.5%CVE-2021-29985A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerabilityEPSS 1.5%CVE-2019-11744Some HTML elements, such as &lt;title&gt; and &lt;textarea&gt;, can contain literal angle brackets without treating them as markup. It is poEPSS 1.5%CVE-2019-11738If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of anyEPSS 1.4%CVE-2018-12371An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. TEPSS 1.4%CVE-2018-5176The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file containsEPSS 1.4%CVE-2018-5167The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, cliEPSS 1.4%CVE-2017-5426On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox failsEPSS 1.4%CVE-2021-29970A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be tEPSS 1.4%CVE-2020-6826Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showedEPSS 1.4%