Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-0880HIGHSandbox escape due to integer overflow in the Graphics componentEPSS 0.7%CVE-2019-25136CRITICALA compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox EPSS 0.7%CVE-2023-4574—Memory corruption in IPC ColorPickerShownCallbackEPSS 0.7%CVE-2022-3032—When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HEPSS 0.7%CVE-2022-31739HIGHWhen downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-EPSS 0.7%CVE-2025-49709CRITICALMemory corruption in canvas surfacesEPSS 0.7%CVE-2022-31741HIGHA crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. TEPSS 0.7%CVE-2024-6611CRITICALIncorrect handling of SameSite cookiesEPSS 0.7%CVE-2024-0745HIGHThe WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. ThiEPSS 0.7%CVE-2022-36320CRITICALMozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of meEPSS 0.7%CVE-2023-4051—Full screen notification obscured by file open dialogEPSS 0.7%CVE-2023-4575—Memory corruption in IPC FilePickerShownCallbackEPSS 0.7%CVE-2022-26387HIGHWhen installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underEPSS 0.7%CVE-2021-23955—The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks.EPSS 0.7%CVE-2021-23963—When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to EPSS 0.7%CVE-2024-7652HIGHType Confusion in Async Generators in Javascript EngineEPSS 0.7%CVE-2022-31748CRITICALMozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs prEPSS 0.7%CVE-2026-2796CRITICALJIT miscompilation in the JavaScript: WebAssembly componentEPSS 0.7%CVE-2024-11705CRITICAL`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV)EPSS 0.7%CVE-2022-26383MEDIUMWhen resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affectEPSS 0.7%