Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2021-23956—An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. EPSS 1.0%CVE-2022-22738HIGHApplying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially EPSS 1.0%CVE-2024-6602CRITICALMemory corruption in NSSEPSS 1.0%CVE-2023-5731—Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 1.0%CVE-2019-17013—Mozilla developers reported memory safety bugs present in Firefox 70. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2022-34484HIGHThe Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruEPSS 1.0%CVE-2020-12398—If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue witEPSS 1.0%CVE-2020-12407—Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visEPSS 1.0%CVE-2023-29531CRITICALAn attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crEPSS 1.0%CVE-2024-2612HIGHIf an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveragEPSS 1.0%CVE-2021-23965—Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2023-5732—Address bar spoofing via bidirectional charactersEPSS 1.0%CVE-2021-29975—Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlEPSS 1.0%CVE-2020-15646—If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanEPSS 1.0%CVE-2022-22740HIGHCertain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causiEPSS 1.0%CVE-2020-12408—When browsing a document hosted on an IP address, an attacker could insert certain characters to flip domain and path information in the addEPSS 1.0%CVE-2023-6860—The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. ThisEPSS 1.0%CVE-2019-9818—A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-EPSS 1.0%CVE-2023-6862—A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affeEPSS 1.0%CVE-2023-4056—Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bEPSS 0.9%