Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2017-5426On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox failsEPSS 1.4%CVE-2021-29970A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be tEPSS 1.4%CVE-2020-6826Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showedEPSS 1.4%CVE-2017-5458When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users toEPSS 1.4%CVE-2018-18497Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used withEPSS 1.4%CVE-2018-12388Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corEPSS 1.4%CVE-2017-7774Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.EPSS 1.4%CVE-2017-7773Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.EPSS 1.4%CVE-2017-7772Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.EPSS 1.4%CVE-2021-23987Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed eEPSS 1.4%CVE-2020-35111When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-sourceEPSS 1.4%CVE-2019-11733When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It wEPSS 1.4%CVE-2023-6861The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects EPSS 1.4%CVE-2020-6801Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.4%CVE-2023-6209Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override thEPSS 1.4%CVE-2017-7799JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usageEPSS 1.4%CVE-2021-29980Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable craEPSS 1.4%CVE-2020-12387A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitableEPSS 1.4%CVE-2021-43546It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects ThunderbiEPSS 1.4%CVE-2019-17007In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of serviceEPSS 1.4%