Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2020-15653An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues forEPSS 1.4%CVE-2019-11721The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks aEPSS 1.4%CVE-2021-43530A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QEPSS 1.4%CVE-2017-7755The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This EPSS 1.4%CVE-2021-29984Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collectEPSS 1.4%CVE-2021-29988Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a pEPSS 1.4%CVE-2020-15664By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTriggerEPSS 1.4%CVE-2018-18503When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatcEPSS 1.4%CVE-2021-23999If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional priEPSS 1.4%CVE-2019-11700A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution whEPSS 1.4%CVE-2019-11760A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some iEPSS 1.4%CVE-2025-1015MEDIUMUnsanitized address book fieldsEPSS 1.4%CVE-2021-23973When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may EPSS 1.4%CVE-2021-29967Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corEPSS 1.4%CVE-2019-11702A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with InEPSS 1.4%CVE-2021-21354HIGHOpen redirect in pollbotEPSS 1.4%CVE-2020-26958Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. TEPSS 1.4%CVE-2017-7822The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NIST Special PublicatiEPSS 1.4%CVE-2020-6815Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruptEPSS 1.4%CVE-2017-7765The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the MarkEPSS 1.4%