Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2020-26967—When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elemeEPSS 0.9%CVE-2022-26381HIGHAn attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vuEPSS 0.8%CVE-2020-15685HIGHDuring the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted sEPSS 0.8%CVE-2021-4138—Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified hostname.EPSS 0.8%CVE-2020-26963—Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by introducing rate-limitEPSS 0.8%CVE-2019-11697—If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the installEPSS 0.8%CVE-2019-9821—A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exEPSS 0.8%CVE-2020-15661—A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for thEPSS 0.8%CVE-2019-11765—A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown.EPSS 0.8%CVE-2019-11699—A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This couldEPSS 0.8%CVE-2023-5175CRITICALDuring process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepEPSS 0.8%CVE-2021-29974—When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to oEPSS 0.8%CVE-2017-7808—A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths insteadEPSS 0.8%CVE-2019-11696—Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even thoughEPSS 0.8%CVE-2021-29959—When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website fromEPSS 0.8%CVE-2024-0750HIGHA bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vEPSS 0.8%CVE-2023-6204—On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the EPSS 0.8%CVE-2022-42928HIGHCertain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corrEPSS 0.8%CVE-2013-1689—Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.EPSS 0.8%CVE-2023-6212—Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruptionEPSS 0.8%