Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-8964HIGHSpoofing issue in the Popup Blocker componentEPSS 0.4%CVE-2022-42930HIGHIf two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This EPSS 0.4%CVE-2025-1014HIGHCertificate length was not properly checkedEPSS 0.4%CVE-2024-6601MEDIUMRace condition in permission assignmentEPSS 0.4%CVE-2025-3032HIGHLeaking file descriptors from the fork serverEPSS 0.4%CVE-2024-8386MEDIUMIf a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform EPSS 0.4%CVE-2026-16368CRITICALIncorrect boundary conditions in the JavaScript: WebAssembly componentEPSS 0.4%CVE-2026-16377CRITICALMitigation bypass in the PDF Viewer componentEPSS 0.4%CVE-2024-0605HIGHUsing a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bEPSS 0.4%CVE-2026-16383CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.4%CVE-2024-1563HIGHAn attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom FEPSS 0.4%CVE-2026-6756HIGHMitigation bypass in Firefox for AndroidEPSS 0.4%CVE-2026-4712HIGHInformation disclosure in the Widget: Cocoa componentEPSS 0.4%CVE-2024-2608HIGH`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows,EPSS 0.4%CVE-2023-25749MEDIUMAndroid applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities. FEPSS 0.4%CVE-2023-6870—Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. *ThisEPSS 0.4%CVE-2017-7766—An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla MaEPSS 0.4%CVE-2024-5698MEDIUMBy manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This coulEPSS 0.4%CVE-2026-12291HIGHUse-after-free in the Networking: HTTP componentEPSS 0.4%CVE-2024-1554CRITICALThe `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contEPSS 0.4%