Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2011-2669—Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.EPSS 0.6%CVE-2026-84142CRITICALInternally found bugs fixed in Thunderbird 155EPSS 0.6%CVE-2022-28286MEDIUMDue to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing atEPSS 0.6%CVE-2022-29911MEDIUMAn improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execuEPSS 0.6%CVE-2022-0843HIGHMozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugsEPSS 0.6%CVE-2022-22763HIGHWhen a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. TEPSS 0.6%CVE-2026-2781HIGHInteger overflow in the Libraries component in NSSEPSS 0.6%CVE-2023-6869MEDIUMA `&lt;dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to diEPSS 0.6%CVE-2019-9803—The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-EPSS 0.6%CVE-2024-1557HIGHMemory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.6%CVE-2023-25731HIGHDue to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwriteEPSS 0.6%CVE-2026-2806CRITICALUninitialized memory in the Graphics: Text componentEPSS 0.6%CVE-2023-29537—Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnEPSS 0.6%CVE-2026-8391MEDIUMOther issue in the JavaScript Engine componentEPSS 0.6%CVE-2026-74986CRITICALSite isolation issue in the CSS Parsing and Computation componentEPSS 0.6%CVE-2022-26385MEDIUMIn unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free cauEPSS 0.6%CVE-2022-34477HIGHThe MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site crosEPSS 0.6%CVE-2025-1937HIGHMemory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8EPSS 0.6%CVE-2022-28287MEDIUMIn unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability afEPSS 0.5%CVE-2020-26957—OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce EPSS 0.5%