Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-74953HIGHPrivilege escalation in the Networking: Cookies componentEPSS 0.4%CVE-2026-74965HIGHPrivilege escalation in the Shell Integration componentEPSS 0.4%CVE-2026-92047HIGHPrivilege escalation in the Crash Reporting componentEPSS 0.4%CVE-2026-74961CRITICALSide-channel in the Web Audio componentEPSS 0.4%CVE-2026-92062HIGHPrivilege escalation in the Session Restore componentEPSS 0.4%CVE-2026-92055HIGHPrivilege escalation in the DevTools componentEPSS 0.4%CVE-2026-92073HIGHPrivilege escalation in the Enterprise Policies componentEPSS 0.4%CVE-2025-13016HIGHIncorrect boundary conditions in the JavaScript: WebAssembly componentEPSS 0.4%CVE-2026-74938CRITICALMitigation bypass in the JavaScript: GC componentEPSS 0.4%CVE-2016-5291—A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45EPSS 0.4%CVE-2025-14333HIGHMemory safety bugs fixed in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146EPSS 0.4%CVE-2026-74948MEDIUMInformation disclosure in the Graphics componentEPSS 0.4%CVE-2024-4778CRITICALMemory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.4%CVE-2026-74945MEDIUMInformation disclosure in the Graphics: Text componentEPSS 0.4%CVE-2024-5700HIGHMemory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruptiEPSS 0.4%CVE-2026-84130HIGHInformation disclosure in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-84132HIGHInformation disclosure in the Networking: HTTP componentEPSS 0.4%CVE-2026-74954HIGHInformation disclosure due to side-channel in the Storage: Cache API componentEPSS 0.4%CVE-2026-74966HIGHInformation disclosure in the Form Autofill componentEPSS 0.4%CVE-2026-8958HIGHInformation disclosure, sandbox escape in the Security: Process Sandboxing componentEPSS 0.4%