Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2017-5390The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers EPSS 3.9%CVE-2021-38503The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scriptsEPSS 3.8%CVE-2018-5177A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a bufferEPSS 3.8%CVE-2018-12362An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in aEPSS 3.8%CVE-2017-5397The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allEPSS 3.8%CVE-2018-5156A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result iEPSS 3.8%CVE-2017-5398Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enougEPSS 3.7%CVE-2025-6424CRITICALUse-after-free in FontFaceSetEPSS 3.6%CVE-2016-5297An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerabiliEPSS 3.6%CVE-2017-7824A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incEPSS 3.6%CVE-2017-5400JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruptionEPSS 3.6%CVE-2017-5439A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitableEPSS 3.6%CVE-2017-5434A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability aEPSS 3.6%CVE-2017-5438A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results EPSS 3.6%CVE-2017-5433A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animaEPSS 3.6%CVE-2019-17006In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application cEPSS 3.6%CVE-2016-9898Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox <EPSS 3.5%CVE-2025-6436HIGHMemory safety bugs fixed in Firefox 140 and Thunderbird 140EPSS 3.5%CVE-2017-5455The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with anoEPSS 3.5%CVE-2016-5296A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. TEPSS 3.5%