Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2022-46873HIGHBecause Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwEPSS 0.7%CVE-2023-23605HIGHMemory safety bugs fixed in Firefox 109 and Firefox ESR 102.7EPSS 0.7%CVE-2023-28162HIGHWhile implementing AudioWorklets, some code may have casted one type to another, invalid, dynamic type. This could have led to a potentiallyEPSS 0.7%CVE-2021-29944—Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execuEPSS 0.7%CVE-2022-45421HIGHMozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed EPSS 0.7%CVE-2023-29536—An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertioEPSS 0.7%CVE-2022-0566HIGHIt may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when procEPSS 0.7%CVE-2022-34476CRITICALASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulneraEPSS 0.7%CVE-2022-45408MEDIUMThrough a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification pEPSS 0.7%CVE-2024-2616LOWTo harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnEPSS 0.7%CVE-2024-11691HIGHCertain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in EPSS 0.7%CVE-2022-46877MEDIUMBy confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofiEPSS 0.7%CVE-2020-26962—Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have beEPSS 0.7%CVE-2011-2670—Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style SheetsEPSS 0.7%CVE-2022-28289HIGHMozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safetEPSS 0.7%CVE-2022-45403MEDIUMService Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media cEPSS 0.7%CVE-2023-29548MEDIUMA wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, FoEPSS 0.7%CVE-2022-36319HIGHWhen combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vuEPSS 0.7%CVE-2023-5723—An attacker with temporary script access to a site could have set a cookie containing invalid characters using `document.cookie` that could EPSS 0.7%CVE-2024-10463HIGHVideo frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, FirefEPSS 0.7%