Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2022-22760MEDIUMWhen importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> respEPSS 0.8%CVE-2022-28285MEDIUMWhen generating the assembly code for <code>MLoadTypedArrayElementHole</code>, an incorrect AliasSet was used. In conjunction with another vEPSS 0.8%CVE-2023-4421—The NSS code used for checking PKCS#1 v1.5 was leaking information useful in mounting Bleichenbacher-like attacks. Both the overall correctnEPSS 0.8%CVE-2023-37202—Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment EPSS 0.8%CVE-2023-37201—An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects FirefoxEPSS 0.8%CVE-2021-23974—The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML SanitiEPSS 0.8%CVE-2023-32213—When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.EPSS 0.8%CVE-2023-37211—Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruptiEPSS 0.8%CVE-2023-32215—Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the MozillaEPSS 0.8%CVE-2024-0755HIGHMemory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruptionEPSS 0.8%CVE-2020-6804HIGHXSS in Mozilla WebThings GatewayEPSS 0.7%CVE-2022-2505HIGHMozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of meEPSS 0.7%CVE-2023-29535—Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corrupEPSS 0.7%CVE-2021-29962—Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affects Firefox for AndrEPSS 0.7%CVE-2022-45410MEDIUMWhen a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownEPSS 0.7%CVE-2022-34479MEDIUMA malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potEPSS 0.7%CVE-2022-22737HIGHConstructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-aftEPSS 0.7%CVE-2025-49710CRITICALInteger overflow in OrderedHashTableEPSS 0.7%CVE-2022-22759CRITICALIf a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document tEPSS 0.7%CVE-2022-22761HIGHWeb-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it wasEPSS 0.7%