Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2019-11761—By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact fEPSS 0.9%CVE-2024-11704CRITICALA double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the sEPSS 0.9%CVE-2021-29991—Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attEPSS 0.9%CVE-2019-9798—On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow maliciouEPSS 0.9%CVE-2022-38478HIGHMembers the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of theseEPSS 0.9%CVE-2020-6830—For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That toEPSS 0.9%CVE-2021-4127CRITICALAn out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects ThuEPSS 0.9%CVE-2019-11739—Encrypted S/MIME parts in a crafted multipart/alternative message can leak plaintext when included in a a HTML reply/forward. This vulnerabiEPSS 0.9%CVE-2023-34414—The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialoEPSS 0.9%CVE-2017-5393—The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could EPSS 0.9%CVE-2019-11749—A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal EPSS 0.9%CVE-2022-46871HIGHAn out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.EPSS 0.9%CVE-2022-38477HIGHMozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some oEPSS 0.9%CVE-2023-4582HIGHBuffer Overflow in WebGL glGetProgramivEPSS 0.9%CVE-2023-6865—`EncryptingOutputStream` was susceptible to exposing uninitialized data. This issue could only be abused in order to write data to a local EPSS 0.9%CVE-2023-4057—Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruptionEPSS 0.9%CVE-2024-2614HIGHMemory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruptionEPSS 0.9%CVE-2021-23962—Incorrect use of the '<RowCountChanged>' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerabilitEPSS 0.9%CVE-2022-40956MEDIUMWhen injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. EPSS 0.9%CVE-2022-46874HIGHA file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place.EPSS 0.9%