Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2017-7792A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifieEPSS 3.2%CVE-2018-12390Mozilla developers and community members reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed eEPSS 3.2%CVE-2018-12405Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed eEPSS 3.2%CVE-2017-5376Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51EPSS 3.2%CVE-2016-5290Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume EPSS 3.2%CVE-2017-7845A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. ThiEPSS 3.2%CVE-2017-5380A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, FireEPSS 3.2%CVE-2018-12366An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This couEPSS 3.2%CVE-2018-12365A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consentEPSS 3.2%CVE-2018-12376Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that wEPSS 3.1%CVE-2017-7753An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerabilityEPSS 3.1%CVE-2017-5435A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentiEPSS 3.1%CVE-2017-5432A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability aEPSS 3.1%CVE-2018-5183Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer EPSS 3.1%CVE-2018-5150Memory safety bugs were reported in Firefox 59, Firefox ESR 52.7, and Thunderbird 52.7. Some of these bugs showed evidence of memory corruptEPSS 3.1%CVE-2017-7805During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in EPSS 3.1%CVE-2018-12360A use-after-free vulnerability can occur when deleting an input element during a mutation event handler triggered by focusing that element. EPSS 3.1%CVE-2017-7758An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in useEPSS 3.1%CVE-2018-12363A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old documentEPSS 3.1%CVE-2017-5446An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exEPSS 3.1%