Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2023-4047—A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vEPSS 0.6%CVE-2023-4573—Memory corruption in IPC CanvasTranslatorEPSS 0.6%CVE-2023-32205—In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusionEPSS 0.6%CVE-2026-84141CRITICALInteger overflow in the Graphics: ImageLib componentEPSS 0.6%CVE-2022-22747MEDIUMAfter accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This EPSS 0.6%CVE-2025-2817HIGHPrivilege escalation in Thunderbird UpdaterEPSS 0.6%CVE-2024-7519HIGHInsufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to peEPSS 0.6%CVE-2026-8094CRITICALOther issue in the WebRTC componentEPSS 0.6%CVE-2022-40961MEDIUMDuring startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>EPSS 0.6%CVE-2024-3852HIGHGetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, FireEPSS 0.6%CVE-2022-45407HIGHIf an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentEPSS 0.6%CVE-2022-22753HIGHA Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrarEPSS 0.6%CVE-2026-84637CRITICALCalendar invitation attachments could launch local executablesEPSS 0.6%CVE-2019-11754—When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious websiEPSS 0.6%CVE-2023-28161HIGHIf temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permisEPSS 0.6%CVE-2026-2447HIGHHeap buffer overflow in libvpxEPSS 0.6%CVE-2023-4578—Error reporting methods in SpiderMonkey could have triggered an Out of Memory ExceptionEPSS 0.6%CVE-2023-25733HIGHThe return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null pointer dereference.EPSS 0.6%CVE-2022-29914MEDIUMWhen reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofEPSS 0.6%CVE-2026-2792CRITICALMemory safety bugs fixed in Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148EPSS 0.6%