Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2017-7763—Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domaEPSS 1.3%CVE-2019-11758—Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed eEPSS 1.3%CVE-2020-6822—On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is EPSS 1.3%CVE-2020-26978—Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as sEPSS 1.3%CVE-2017-7817—A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be dispEPSS 1.3%CVE-2017-7815—On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domaEPSS 1.3%CVE-2018-5185—Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and ThEPSS 1.3%CVE-2021-23968—If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation reEPSS 1.3%CVE-2020-6795—When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leaEPSS 1.3%CVE-2021-29946—Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when usedEPSS 1.3%CVE-2017-7774—Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.EPSS 1.3%CVE-2020-26959—During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruEPSS 1.3%CVE-2020-26972—The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting tEPSS 1.3%CVE-2019-11734—Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corEPSS 1.3%CVE-2020-26953—It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishEPSS 1.3%CVE-2017-5382—Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internEPSS 1.3%CVE-2021-23960—Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. ThisEPSS 1.3%CVE-2024-0743HIGHAn unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122,EPSS 1.3%CVE-2022-40959MEDIUMDuring iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissionEPSS 1.3%CVE-2018-12402—The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loEPSS 1.3%