Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2023-25747HIGHA potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug onlEPSS 0.6%CVE-2024-10464HIGHRepeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressEPSS 0.6%CVE-2023-23599—Malicious command could be hidden in devtools output on WindowsEPSS 0.6%CVE-2023-23602MEDIUMContent Security Policy wasn't being correctly applied to WebSockets in WebWorkersEPSS 0.6%CVE-2026-8949HIGHInteger overflow in the Widget: Win32 componentEPSS 0.6%CVE-2024-0747MEDIUMWhen a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child ContEPSS 0.6%CVE-2026-74977HIGHInteger overflow in the Graphics componentEPSS 0.6%CVE-2023-5170—In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileEPSS 0.6%CVE-2024-10459MEDIUMAn attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerabilitEPSS 0.6%CVE-2024-7525CRITICALIt was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response EPSS 0.6%CVE-2026-2770HIGHUse-after-free in the DOM: Bindings (WebIDL) componentEPSS 0.6%CVE-2026-2765CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2026-2772HIGHUse-after-free in the Audio/Video: Playback componentEPSS 0.6%CVE-2026-2767HIGHUse-after-free in the JavaScript: WebAssembly componentEPSS 0.6%CVE-2026-2766CRITICALUse-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-2763CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2026-2764CRITICALJIT miscompilation, use-after-free in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2020-12397—By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird dispEPSS 0.6%CVE-2026-2758CRITICALUse-after-free in the JavaScript: GC componentEPSS 0.6%CVE-2026-6748CRITICALUninitialized memory in the Audio/Video: Web Codecs componentEPSS 0.6%