Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2022-22759CRITICALIf a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document tEPSS 0.7%CVE-2023-29541HIGHFirefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commEPSS 0.7%CVE-2024-1551MEDIUMSet-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type responEPSS 0.7%CVE-2025-0241HIGHMemory corruption when using JavaScript Text SegmentationEPSS 0.7%CVE-2023-37207—A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL.EPSS 0.7%CVE-2023-5173—In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a EPSS 0.7%CVE-2024-9401CRITICALMemory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence EPSS 0.7%CVE-2023-32211—A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and ThundEPSS 0.7%CVE-2024-0746MEDIUMA Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR EPSS 0.7%CVE-2025-10533HIGHInteger overflow in the SVG componentEPSS 0.7%CVE-2023-25732HIGHWhen encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated pEPSS 0.7%CVE-2021-29965—A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords fEPSS 0.7%CVE-2023-29539—When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL chaEPSS 0.7%CVE-2021-29952—When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort maEPSS 0.7%CVE-2024-5690MEDIUMBy monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's EPSS 0.7%CVE-2021-23983—By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memoEPSS 0.7%CVE-2021-29983—Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause it to exit. *Note: TEPSS 0.7%CVE-2024-3854HIGHIn some code patterns the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. This vulnerability affectEPSS 0.7%CVE-2019-11695—A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be alloEPSS 0.7%CVE-2023-4055—When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent witEPSS 0.7%