Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-2793CRITICALMemory safety bugs fixed in Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird ESR 140.8, Firefox 148 and Thunderbird 148EPSS 0.6%CVE-2018-5109—An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow tEPSS 0.6%CVE-2024-7521CRITICALIncomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14,EPSS 0.6%CVE-2024-5692MEDIUMOn Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extEPSS 0.6%CVE-2024-9402CRITICALMemory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruptionEPSS 0.6%CVE-2026-2773CRITICALIncorrect boundary conditions in the Web Audio componentEPSS 0.6%CVE-2023-6210—When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as ifrEPSS 0.6%CVE-2026-2761CRITICALSandbox escape in the Graphics: WebRender componentEPSS 0.6%CVE-2026-2776CRITICALSandbox escape due to incorrect boundary conditions in the Telemetry component in External SoftwareEPSS 0.6%CVE-2026-2757CRITICALIncorrect boundary conditions in the WebRTC: Audio/Video componentEPSS 0.6%CVE-2026-2759CRITICALIncorrect boundary conditions in the Graphics: ImageLib componentEPSS 0.6%CVE-2026-2771CRITICALUndefined behavior in the DOM: Core & HTML componentEPSS 0.6%CVE-2026-2778CRITICALSandbox escape due to incorrect boundary conditions in the DOM: Core & HTML componentEPSS 0.6%CVE-2026-2760CRITICALSandbox escape due to incorrect boundary conditions in the Graphics: WebRender componentEPSS 0.6%CVE-2024-3856HIGHA use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects FirEPSS 0.6%CVE-2026-0879CRITICALSandbox escape due to incorrect boundary conditions in the Graphics componentEPSS 0.6%CVE-2025-0237MEDIUMWebChannel APIs susceptible to confused deputy attackEPSS 0.6%CVE-2022-45404MEDIUMThrough a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing theEPSS 0.6%CVE-2023-25752—When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may haEPSS 0.6%CVE-2026-5731CRITICALMemory safety bugs fixed in Firefox ESR 115.34.1, Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2EPSS 0.6%