Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2023-32216—Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bEPSS 0.8%CVE-2023-34417CRITICALMemory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.8%CVE-2023-6208—When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage notEPSS 0.8%CVE-2022-45409HIGHThe garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been calEPSS 0.8%CVE-2020-12412—By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// schemeEPSS 0.8%CVE-2023-25734HIGHAfter downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to EPSS 0.8%CVE-2022-3033HIGHIf a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>htEPSS 0.8%CVE-2023-4585HIGHMemory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2EPSS 0.8%CVE-2024-5699CRITICALIn violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be EPSS 0.8%CVE-2017-5394—A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScEPSS 0.8%CVE-2022-46872HIGHAn attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC mesEPSS 0.8%CVE-2023-4053—Full screen notification obscured by external programEPSS 0.8%CVE-2023-25741MEDIUMWhen dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused EPSS 0.8%CVE-2024-3302LOWThere was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of MemoryEPSS 0.8%CVE-2020-6827—When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into disEPSS 0.8%CVE-2024-11697HIGHWhen handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialogEPSS 0.8%CVE-2016-9077—Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on EPSS 0.8%CVE-2013-4227—Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x bEPSS 0.8%CVE-2023-32209—A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.EPSS 0.8%CVE-2021-29961—When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an attacker to paint over tEPSS 0.8%