Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-16350CRITICALIncorrect boundary conditions in the Audio/Video: cubeb componentEPSS 0.4%CVE-2025-8034HIGHMemory safety bugs fixed in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2026-8963HIGHSpoofing issue in the Web Speech componentEPSS 0.4%CVE-2026-8960HIGHSpoofing issue in WebExtensionsEPSS 0.4%CVE-2025-14329HIGHPrivilege escalation in the Netmonitor componentEPSS 0.4%CVE-2025-14328HIGHPrivilege escalation in the Netmonitor componentEPSS 0.4%CVE-2026-8952HIGHPrivilege escalation in the Application Update componentEPSS 0.4%CVE-2017-5387—The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on aEPSS 0.4%CVE-2026-6770MEDIUMOther issue in the Storage: IndexedDB componentEPSS 0.4%CVE-2026-8962HIGHMitigation bypass in the DOM: Security componentEPSS 0.4%CVE-2023-29538—Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> UREPSS 0.4%CVE-2016-9062—Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" files within the FirEPSS 0.4%CVE-2024-6606HIGHOut-of-bounds read in clipboard componentEPSS 0.4%CVE-2026-8945HIGHSandbox escape in Firefox and Firefox Focus for AndroidEPSS 0.4%CVE-2026-4711CRITICALUse-after-free in the Widget: Cocoa componentEPSS 0.4%CVE-2024-5689MEDIUMIn addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and dEPSS 0.4%CVE-2024-3855MEDIUMIn certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 12EPSS 0.4%CVE-2024-6600MEDIUMMemory corruption in WebGL APIEPSS 0.4%CVE-2026-12290HIGHMemory safety bug fixed in Firefox 152EPSS 0.4%CVE-2019-9808—If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originatEPSS 0.4%