Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2022-42927HIGHA same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.EPSS 0.4%CVE-2023-34415—When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that docuEPSS 0.4%CVE-2022-31746MEDIUMInternal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability aEPSS 0.4%CVE-2024-5687MEDIUMIf a specific sequence of actions is performed when opening a new tab, the triggering principal associated with the new tab may have been inEPSS 0.4%CVE-2019-17003MEDIUMScanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.EPSS 0.4%CVE-2026-2783MEDIUMInformation disclosure due to JIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2026-0885MEDIUMUse-after-free in the JavaScript: GC componentEPSS 0.4%CVE-2021-4221MEDIUMIf a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confuEPSS 0.4%CVE-2022-2226MEDIUMAn OpenPGP digital signature includes information about the date when the signature was created. When displaying an email that contains a diEPSS 0.4%CVE-2026-4710CRITICALIncorrect boundary conditions in the Audio/Video componentEPSS 0.4%CVE-2022-45417MEDIUMService Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk fEPSS 0.4%CVE-2026-92063MEDIUMDenial-of-service in the Audio/Video componentEPSS 0.4%CVE-2017-7760—The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the oEPSS 0.4%CVE-2026-4716CRITICALIncorrect boundary conditions, uninitialized memory in the JavaScript Engine componentEPSS 0.4%CVE-2026-12327HIGHMemory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152EPSS 0.4%CVE-2022-34474MEDIUMEven when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an externalEPSS 0.4%CVE-2026-92239HIGHBuffer overrun in IMAPEPSS 0.4%CVE-2024-10941MEDIUMA malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affEPSS 0.4%CVE-2026-16355CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2026-16357CRITICALIncorrect boundary conditions in the Graphics componentEPSS 0.4%