Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2021-29960—Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web EPSS 0.8%CVE-2022-38476HIGHA data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this EPSS 0.8%CVE-2024-11693CRITICALThe executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systemEPSS 0.8%CVE-2021-29968—When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. OtherEPSS 0.8%CVE-2020-26955—When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operaEPSS 0.8%CVE-2021-38499—Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presumeEPSS 0.8%CVE-2023-5388MEDIUMNSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recovEPSS 0.8%CVE-2023-4576—Integer Overflow in RecordedSourceSurfaceCreationEPSS 0.8%CVE-2026-4694HIGHIncorrect boundary conditions, integer overflow in the Graphics componentEPSS 0.8%CVE-2023-5172CRITICALA hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and EPSS 0.8%CVE-2023-0767HIGHAn attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributesEPSS 0.8%CVE-2021-29964—A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds reEPSS 0.8%CVE-2021-23997—Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enoEPSS 0.8%CVE-2022-31737CRITICALA malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. ThiEPSS 0.8%CVE-2024-3863CRITICALThe executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. OEPSS 0.8%CVE-2021-29973—Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interEPSS 0.8%CVE-2025-0238MEDIUMUse-after-free when breaking lines in textEPSS 0.8%CVE-2021-29956—OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local diEPSS 0.8%CVE-2024-10466HIGHBy sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive.EPSS 0.8%CVE-2019-11723—A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. ThiEPSS 0.8%