Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2024-0742MEDIUMIt was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestaEPSS 0.6%CVE-2026-8091CRITICALIncorrect boundary conditions in the Audio/Video: Playback componentEPSS 0.6%CVE-2024-10467CRITICALMemory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruptionEPSS 0.6%CVE-2025-14321CRITICALUse-after-free in the WebRTC: Signaling componentEPSS 0.6%CVE-2026-8401CRITICALSandbox escape in the Profile Backup componentEPSS 0.6%CVE-2024-2615CRITICALMemory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.6%CVE-2024-8382HIGHInternal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web contEPSS 0.6%CVE-2023-4045—Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violatioEPSS 0.6%CVE-2023-37209—A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSessionHistoryEntry` object was freed and a reference to that EPSS 0.6%CVE-2020-12413MEDIUMThe Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabledEPSS 0.6%CVE-2021-23998—Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerabilitEPSS 0.6%CVE-2022-31742MEDIUMAn attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between iEPSS 0.6%CVE-2026-2769HIGHUse-after-free in the Storage: IndexedDB componentEPSS 0.6%CVE-2024-4770HIGHWhen saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126,EPSS 0.6%CVE-2026-74944CRITICALUse-after-free in the DOM: Core & HTML componentEPSS 0.6%CVE-2026-74936CRITICALUse-after-free in the JavaScript: WebAssembly componentEPSS 0.6%CVE-2025-1016CRITICALMemory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7EPSS 0.6%CVE-2023-5729—A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen noEPSS 0.6%CVE-2026-6750HIGHPrivilege escalation in the Graphics: WebRender componentEPSS 0.6%CVE-2021-38497—Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to poEPSS 0.6%