Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2019-11755—A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signatureEPSS 1.1%CVE-2020-15670—Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption anEPSS 1.1%CVE-2024-5688HIGHIf a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability aEPSS 1.1%CVE-2022-34470CRITICALSession history navigations may have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox < 102, FiEPSS 1.1%CVE-2019-11751—Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks oEPSS 1.1%CVE-2022-45406CRITICALIf an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on EPSS 1.1%CVE-2021-23953—If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said informaEPSS 1.1%CVE-2022-31736CRITICALA malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects ThunderEPSS 1.1%CVE-2020-26951—A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker alreEPSS 1.1%CVE-2021-38505—Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to theEPSS 1.1%CVE-2021-38501—Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corrEPSS 1.0%CVE-2019-11712—POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allowEPSS 1.0%CVE-2019-17019—When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of beiEPSS 1.0%CVE-2021-29972—A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, aEPSS 1.0%CVE-2023-6863—The `ShutdownObserver()` was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destrEPSS 1.0%CVE-2020-35114—Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2021-23991—If a Thunderbird user has previously imported Alice's OpenPGP key, and Alice has extended the validity period of her key, but Alice's updateEPSS 1.0%CVE-2020-6810—After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the broEPSS 1.0%CVE-2019-11748—WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party cEPSS 1.0%CVE-2023-5171—During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes,EPSS 1.0%