Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2023-23598—Arbitrary file read from GTK drag and drop on LinuxEPSS 0.6%CVE-2022-22745MEDIUMSecuritypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects FirefoxEPSS 0.6%CVE-2026-8956CRITICALInteger overflow in the Networking: JAR componentEPSS 0.6%CVE-2023-49060—An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. TEPSS 0.6%CVE-2023-5722—Using iterative requests an attacker was able to learn the size of an opaque response, as well as the contents of a server-supplied Vary heaEPSS 0.6%CVE-2022-46879HIGHMozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported memory safetyEPSS 0.6%CVE-2022-45405MEDIUMFreeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploEPSS 0.6%CVE-2024-7520HIGHA type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects FireEPSS 0.6%CVE-2023-37212—Memory safety bugs present in Firefox 114. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.6%CVE-2024-8383HIGHFirefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does noEPSS 0.6%CVE-2020-15650—Given an installed malicious file picker application, an attacker was able to overwrite local files and thus overwrite Firefox settings (butEPSS 0.6%CVE-2023-25738MEDIUMMembers of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid valuEPSS 0.6%CVE-2023-3600—Use-after-free in workersEPSS 0.6%CVE-2023-4049—Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-afteEPSS 0.6%CVE-2024-7522CRITICALEditor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, FireEPSS 0.6%CVE-2022-46875MEDIUMThe executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*NEPSS 0.6%CVE-2024-0751HIGHA malicious devtools extension could have been used to escalate privileges. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, aEPSS 0.6%CVE-2023-50761—The signature of a digitally signed S/MIME email message may optionally specify the signature creation date and time. If present, ThunderbirEPSS 0.6%CVE-2025-1011CRITICALA bug in WebAssembly code generation could result in a crashEPSS 0.6%CVE-2023-50762—When processing a PGP/MIME payload that contains digitally signed text, the first paragraph of the text was never shown to the user. This isEPSS 0.6%