Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2021-29971—If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port EPSS 1.0%CVE-2021-29966—Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2020-12406—Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enEPSS 1.0%CVE-2020-6794—If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessEPSS 1.0%CVE-2021-4129CRITICALMozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano rEPSS 1.0%CVE-2021-23972—One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this EPSS 1.0%CVE-2020-15675—When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. ThiEPSS 1.0%CVE-2018-18510—The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the broEPSS 1.0%CVE-2021-29981—An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code thatEPSS 1.0%CVE-2016-9064—Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who couEPSS 1.0%CVE-2021-23975—The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this EPSS 1.0%CVE-2020-12393—The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the webEPSS 1.0%CVE-2021-29977—Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2023-5169—A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a poteEPSS 1.0%CVE-2021-29990—Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of these bugs showed evidence of memory corEPSS 1.0%CVE-2021-23971—When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have poEPSS 1.0%CVE-2021-23970—Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerabEPSS 1.0%CVE-2022-29917CRITICALMozilla developers Andrew McCreight, Gabriele Svelto, Tom Ritter and the Mozilla Fuzzing Team reported memory safety bugs present in FirefoxEPSS 1.0%CVE-2021-38510—The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's EPSS 1.0%CVE-2023-5174CRITICALIf Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting inEPSS 1.0%