Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-5734HIGHMemory safety bugs fixed in Firefox ESR 140.9.1, Thunderbird ESR 140.9.1, Firefox 149.0.2 and Thunderbird 149.0.2EPSS 0.6%CVE-2019-11741—A compromised sandboxed content process can perform a Universal Cross-site Scripting (UXSS) attack on content from any site it can cause to EPSS 0.6%CVE-2026-92061CRITICALIncorrect boundary conditions in the Security: Process Sandboxing componentEPSS 0.6%CVE-2026-8975HIGHMemory safety bugs fixed in Firefox ESR 115.36, Firefox ESR 140.11 and Firefox 151EPSS 0.6%CVE-2024-9396HIGHIt is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to mEPSS 0.6%CVE-2026-92036CRITICALIncorrect boundary conditions in the Networking: HTTP componentEPSS 0.6%CVE-2026-92037CRITICALIncorrect boundary conditions in the DOM: Animation componentEPSS 0.6%CVE-2026-92066CRITICALSandbox escape in the Profile Backup componentEPSS 0.6%CVE-2022-22755HIGHBy using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within thEPSS 0.6%CVE-2022-22746MEDIUMA race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticedEPSS 0.6%CVE-2022-31738MEDIUMWhen exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user cEPSS 0.6%CVE-2023-29545MEDIUMSimilar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resoEPSS 0.6%CVE-2024-8387CRITICALMemory safety bugs present in Firefox 129, Firefox ESR 128.1, and Thunderbird 128.1. Some of these bugs showed evidence of memory corruptionEPSS 0.6%CVE-2024-2605MEDIUMAn attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue onlEPSS 0.6%CVE-2026-2779CRITICALIncorrect boundary conditions in the Networking: JAR componentEPSS 0.6%CVE-2020-15651—A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the fiEPSS 0.6%CVE-2022-1887CRITICALThe search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.EPSS 0.6%CVE-2026-6773HIGHDenial-of-service due to integer overflow in the Graphics: WebGPU componentEPSS 0.6%CVE-2022-31744MEDIUMAn attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's ContenEPSS 0.6%CVE-2024-7526HIGHANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from mEPSS 0.6%