Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2017-5461Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 aEPSS 4.4%CVE-2018-12368Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded fromEPSS 4.4%CVE-2017-7778A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use EPSS 4.1%CVE-2018-5144An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerabilEPSS 4.1%CVE-2018-18493A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the useEPSS 4.0%CVE-2018-12359A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing daEPSS 4.0%CVE-2017-5396A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are frEPSS 3.9%CVE-2021-38503The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scriptsEPSS 3.8%CVE-2018-18505An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpEPSS 3.7%CVE-2017-5469Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1EPSS 3.6%CVE-2018-5095An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 8 GB of RAM. ThEPSS 3.6%CVE-2018-5178A buffer overflow was found during UTF8 to Unicode string conversion within JavaScript with extremely large amounts of data. This vulnerabilEPSS 3.6%CVE-2025-6424CRITICALUse-after-free in FontFaceSetEPSS 3.6%CVE-2018-5188Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and EPSS 3.6%CVE-2017-5390The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers EPSS 3.6%CVE-2017-5459A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird EPSS 3.6%CVE-2019-17006In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application cEPSS 3.6%CVE-2018-18498A potential vulnerability leading to an integer overflow can occur during buffer size calculations for images when a raw value is used insteEPSS 3.6%CVE-2018-12362An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in aEPSS 3.5%CVE-2025-6436HIGHMemory safety bugs fixed in Firefox 140 and Thunderbird 140EPSS 3.5%