Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2025-4919HIGHOut-of-bounds access when optimizing linear sumsEPSS 8.6%CVE-2018-12387A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer beiEPSS 8.4%CVE-2018-5093A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. ThEPSS 7.8%CVE-2024-8897MEDIUMUnder certain conditions, an attacker with the ability to redirect users to a malicious site via an open redirect on a trusted site, may be EPSS 7.6%CVE-2020-6820HIGHUnder certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in tEPSS 7.1%KEVCVE-2017-7828A use-after-free vulnerability can occur when flushing and resizing layout because the "PressShell" object has been freed while still in useEPSS 6.7%CVE-2018-5127A buffer overflow can occur when manipulating the SVG "animatedPathSegList" through script. This results in a potentially exploitable crash.EPSS 6.7%CVE-2018-5104A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentiaEPSS 6.6%CVE-2018-5097A use-after-free vulnerability can occur during XSL transformations when the source document for the transformation is manipulated by scriptEPSS 6.6%CVE-2025-0244MEDIUMAddress bar spoofing using an invalid protocol scheme on Firefox for AndroidEPSS 6.5%CVE-2018-5102A use-after-free vulnerability can occur when manipulating HTML media elements with media streams, resulting in a potentially exploitable crEPSS 6.4%CVE-2019-9813Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read anEPSS 6.3%CVE-2018-5094A heap buffer overflow vulnerability may occur in WebAssembly when "shrinkElements" is called followed by garbage collection on memory that EPSS 5.9%CVE-2020-6831A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially EPSS 5.8%CVE-2016-9063An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.EPSS 5.5%CVE-2019-9816A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypasEPSS 4.9%CVE-2024-29944HIGHAn attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent proceEPSS 4.7%CVE-2018-5100A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scrEPSS 4.7%CVE-2026-6770MEDIUMOther issue in the Storage: IndexedDB componentEPSS 4.7%CVE-2024-8381CRITICALA potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environmenEPSS 4.4%