Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2024-9393HIGHAn attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This coulEPSS 0.4%CVE-2026-12289HIGHPrivilege escalation in the Graphics: WebRender componentEPSS 0.4%CVE-2024-5697MEDIUMA website was able to detect when a user took a screenshot of a page using the built-in Screenshot functionality in Firefox. This vulnerabilEPSS 0.4%CVE-2026-3845HIGHHeap buffer overflow in the Audio/Video: Playback component in Firefox for AndroidEPSS 0.4%CVE-2026-6764MEDIUMIncorrect boundary conditions in the DOM: Device Interfaces componentEPSS 0.4%CVE-2022-34475MEDIUMSVG <code>&lt;use&gt;</code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitEPSS 0.4%CVE-2026-16356CRITICALSandbox escape due to use-after-free in the Disability Access APIs componentEPSS 0.4%CVE-2022-38474MEDIUMA website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not alloEPSS 0.4%CVE-2026-16352CRITICALSandbox escape due to use-after-free in the Disability Access APIs componentEPSS 0.4%CVE-2026-16351CRITICALSandbox escape due to use-after-free in the DOM: Navigation componentEPSS 0.4%CVE-2025-54145CRITICALScanning a malicious URL utilizing Firefox's open-text scheme with the QR code scanner could load arbitrary websitesEPSS 0.4%CVE-2018-12379—When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading EPSS 0.4%CVE-2026-12296CRITICALSandbox escape in the Security: Process Sandboxing componentEPSS 0.4%CVE-2024-10468CRITICALPotential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability aEPSS 0.4%CVE-2026-12297CRITICALSandbox escape due to incorrect boundary conditions in the Networking componentEPSS 0.4%CVE-2026-12295CRITICALSandbox escape in the DOM: Navigation componentEPSS 0.4%CVE-2024-11701MEDIUMThe incorrect domain may have been displayed in the address bar during an interrupted navigation attempt. This could have led to user confusEPSS 0.4%CVE-2025-1930HIGHAudioIPC StreamData could trigger a use-after-free in the Browser processEPSS 0.4%CVE-2024-4766MEDIUMDifferent techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusioEPSS 0.4%CVE-2026-8969HIGHMitigation bypass in the DOM: Security componentEPSS 0.4%