Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-2762CRITICALInteger overflow in the JavaScript: Standard Library componentEPSS 0.7%CVE-2026-92240CRITICALOut-of-bounds read in IMAP response parserEPSS 0.7%CVE-2022-38473HIGHA cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). ThisEPSS 0.7%CVE-2023-25751—Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could leaEPSS 0.7%CVE-2026-2774HIGHInteger overflow in the Audio/Video componentEPSS 0.7%CVE-2024-11698CRITICALA flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialEPSS 0.7%CVE-2020-15665—Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulEPSS 0.7%CVE-2023-25736CRITICALAn invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.EPSS 0.7%CVE-2023-4583HIGHBrowsing Context potentially not cleared when closing Private WindowEPSS 0.7%CVE-2026-74964CRITICALInteger overflow in the Graphics componentEPSS 0.7%CVE-2013-5594—Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml bindingEPSS 0.7%CVE-2023-6867—The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission proEPSS 0.7%CVE-2024-11699HIGHMemory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruptionEPSS 0.7%CVE-2024-1936HIGHThe encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird'sEPSS 0.7%CVE-2023-25739HIGHModule load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoaEPSS 0.7%CVE-2023-25729HIGHPermission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to opeEPSS 0.7%CVE-2023-6866HIGHTypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always EPSS 0.7%CVE-2022-26386MEDIUMPreviously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior wEPSS 0.7%CVE-2022-22739MEDIUMMalicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affectEPSS 0.7%CVE-2024-1547MEDIUMThrough a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victEPSS 0.7%