Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2019-9814—Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corEPSS 1.3%CVE-2018-12358—Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malicious site to read resEPSS 1.3%CVE-2021-38500—Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corrEPSS 1.3%CVE-2018-5106—Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error lEPSS 1.3%CVE-2021-29989—Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corEPSS 1.3%CVE-2021-43528—Thunderbird unexpectedly enabled JavaScript in the composition area. The JavaScript execution context was limited to this area and did not rEPSS 1.3%CVE-2020-12415—When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a suEPSS 1.3%CVE-2021-24002—When a user clicked on an FTP URL containing encoded newline characters (%0A and %0D), the newlines would have been interpreted as such and EPSS 1.3%CVE-2021-29986—A suspected race condition when calling getaddrinfo led to memory corruption and a potentially exploitable crash. *Note: This issue only affEPSS 1.3%CVE-2017-5381—The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashEPSS 1.3%CVE-2020-15652—By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This appliEPSS 1.3%CVE-2020-26965—Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typedEPSS 1.3%CVE-2017-5418—An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the readiEPSS 1.3%CVE-2017-7812—If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be alEPSS 1.3%CVE-2017-7816—WebExtensions could use popups and panels in the extension UI to load an "about:" privileged URL, violating security checks that disallow thEPSS 1.3%CVE-2020-35112—If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable fileEPSS 1.3%CVE-2016-5298—A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when tEPSS 1.3%CVE-2019-17025—Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.3%CVE-2019-11750—A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 andEPSS 1.3%CVE-2016-9069—A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability afEPSS 1.3%