Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2024-0754MEDIUMSome WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.EPSS 0.4%CVE-2025-1943HIGHMemory safety bugs fixed in Firefox 136 and Thunderbird 136EPSS 0.4%CVE-2026-84144HIGHInternally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2EPSS 0.4%CVE-2026-8965HIGHInformation disclosure in the DOM: Security componentEPSS 0.4%CVE-2026-8967HIGHInformation disclosure in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-8966HIGHInformation disclosure in the IP Protection componentEPSS 0.4%CVE-2026-6782HIGHInformation disclosure in the IP Protection componentEPSS 0.4%CVE-2026-74976MEDIUMJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2025-8036HIGHDNS rebinding circumvents CORSEPSS 0.4%CVE-2026-4721CRITICALMemory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149EPSS 0.4%CVE-2026-4720CRITICALMemory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149EPSS 0.4%CVE-2021-23993—An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpeEPSS 0.4%CVE-2026-92077MEDIUMDenial-of-service in the SVG componentEPSS 0.4%CVE-2018-5105—WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file runnEPSS 0.4%CVE-2026-92078MEDIUMDenial-of-service in the Security componentEPSS 0.4%CVE-2022-38475MEDIUMAn attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the valueEPSS 0.4%CVE-2025-11709CRITICALOut of bounds read/write in a privileged process triggered by WebGL texturesEPSS 0.4%CVE-2025-11710CRITICALCross-process information leaked due to malicious IPC messagesEPSS 0.4%CVE-2023-4580—Push notifications saved to disk unencryptedEPSS 0.4%CVE-2026-8093HIGHMemory safety bugs fixed in Firefox 150.0.2EPSS 0.4%