Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-92038CRITICALMitigation bypass in the Remote Settings Client componentEPSS 0.5%CVE-2026-92079CRITICALMitigation bypass in the Widget: Win32 componentEPSS 0.5%CVE-2026-92041CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.5%CVE-2026-92075CRITICALMitigation bypass in the Networking componentEPSS 0.5%CVE-2025-3030HIGHMemory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9EPSS 0.5%CVE-2024-9399HIGHA website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service conEPSS 0.5%CVE-2023-6211—If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked EPSS 0.5%CVE-2023-23600—Notification permissions persisted between Normal and Private Browsing on AndroidEPSS 0.5%CVE-2023-6868—In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined oneEPSS 0.5%CVE-2026-16411CRITICALMemory safety bugs fixed in Firefox 153EPSS 0.5%CVE-2022-26382MEDIUMWhile the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel atEPSS 0.5%CVE-2026-12292HIGHIncorrect boundary conditions in the Web Audio componentEPSS 0.5%CVE-2023-6871—Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. This vulnerability EPSS 0.5%CVE-2024-4767MEDIUMIf the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. ThisEPSS 0.5%CVE-2023-29546MEDIUMWhen recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leakingEPSS 0.5%CVE-2026-74946HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.5%CVE-2023-0616MEDIUMIf a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, EPSS 0.5%CVE-2024-11694MEDIUMEnhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeEPSS 0.5%CVE-2024-8389CRITICALMemory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2024-7524MEDIUMFirefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by ContEPSS 0.5%