Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2016-5294—The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulEPSS 0.4%CVE-2024-0752MEDIUMA use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted iEPSS 0.4%CVE-2024-4776HIGHA file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126EPSS 0.4%CVE-2026-4717CRITICALPrivilege escalation in the Netmonitor componentEPSS 0.4%CVE-2022-22749MEDIUMWhen scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.<br>*This bug only aEPSS 0.4%CVE-2026-84642HIGHAllowed UNC hostnames for attachments interpreted as a regular expressionEPSS 0.4%CVE-2025-1018HIGHFullscreen notification is not displayed when fullscreen is re-requestedEPSS 0.4%CVE-2026-6784HIGHMemory safety bugs fixed in Firefox 150 and Thunderbird 150EPSS 0.4%CVE-2026-74950HIGHPrivilege escalation in the Downloads API componentEPSS 0.4%CVE-2026-74955HIGHPrivilege escalation in the Request Handling componentEPSS 0.4%CVE-2026-8957HIGHPrivilege escalation in the Enterprise Policies componentEPSS 0.4%CVE-2026-8955HIGHPrivilege escalation in the DOM: Workers componentEPSS 0.4%CVE-2025-1932HIGHInconsistent comparator in XSLT sorting led to out-of-bounds accessEPSS 0.4%CVE-2026-74952HIGHPrivilege escalation in the Application Update componentEPSS 0.4%CVE-2026-6769HIGHPrivilege escalation in the Debugger componentEPSS 0.4%CVE-2026-8970HIGHPrivilege escalation in the Security componentEPSS 0.4%CVE-2026-6761HIGHPrivilege escalation in the Networking componentEPSS 0.4%CVE-2025-14323HIGHPrivilege escalation in the DOM: Notifications componentEPSS 0.4%CVE-2025-55031CRITICALPasskey phishing within Bluetooth rangeEPSS 0.4%CVE-2020-12423—When the Windows DLL "webauthn.dll" was missing from the Operating System, and a malicious one was placed in a folder in the user's %PATH%, EPSS 0.4%