Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2021-23977—Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data fromEPSS 0.9%CVE-2019-17018—When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This EPSS 0.9%CVE-2022-31747CRITICALMozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 andEPSS 0.9%CVE-2021-23958—The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. ThiEPSS 0.9%CVE-2021-38491—Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox EPSS 0.9%CVE-2023-5727—The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on aEPSS 0.9%CVE-2021-29947—Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corEPSS 0.9%CVE-2023-6205—It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash.EPSS 0.9%CVE-2024-1553HIGHMemory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruptionEPSS 0.9%CVE-2021-43540—WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been EPSS 0.9%CVE-2022-22751HIGHMozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve EPSS 0.9%CVE-2020-26975—When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been spEPSS 0.9%CVE-2024-5702HIGHMemory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, FirefEPSS 0.9%CVE-2026-10702MEDIUMJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.9%CVE-2025-3028MEDIUMUse-after-free triggered by XSLTProcessorEPSS 0.9%CVE-2022-29909HIGHDocuments in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the exiEPSS 0.9%CVE-2024-3864HIGHMemory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we preEPSS 0.9%CVE-2023-6873—Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.9%CVE-2021-29950—Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure,EPSS 0.9%CVE-2020-26977—By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar dispEPSS 0.9%