Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-74978HIGHClickjacking issue in the Widget componentEPSS 0.4%CVE-2024-7530CRITICALIncorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.EPSS 0.4%CVE-2026-6767MEDIUMOther issue in the Libraries component in NSSEPSS 0.4%CVE-2024-31392HIGHIf an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status ThiEPSS 0.4%CVE-2024-10004CRITICALOpening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in tEPSS 0.4%CVE-2025-8043CRITICALIncorrect URL truncationEPSS 0.4%CVE-2026-92005MEDIUMUse-after-free in the Audio/Video: Web Codecs componentEPSS 0.4%CVE-2026-6783MEDIUMIncorrect boundary conditions, integer overflow in the Audio/Video: Playback componentEPSS 0.4%CVE-2022-1834MEDIUMWhen displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird EPSS 0.4%CVE-2025-3875HIGHSender Spoofing via Malformed From Header in ThunderbirdEPSS 0.4%CVE-2026-84136CRITICALOther issue in the DOM: Navigation componentEPSS 0.4%CVE-2025-8027MEDIUMJavaScript engine only wrote partial return value to stackEPSS 0.4%CVE-2025-14327HIGHSpoofing issue in the Downloads Panel componentEPSS 0.4%CVE-2025-8033MEDIUMIncorrect JavaScript state machine for generatorsEPSS 0.4%CVE-2026-84143CRITICALInternally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15EPSS 0.4%CVE-2026-16382CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.4%CVE-2024-6608MEDIUMCursor could be moved out of the viewport using pointerlock.EPSS 0.4%CVE-2025-9182HIGHDenial-of-service due to out-of-memory in the Graphics: WebRender componentEPSS 0.4%CVE-2026-16367CRITICALSandbox escape due to invalid pointer in the Disability Access APIs componentEPSS 0.4%CVE-2026-3847HIGHMemory safety bugs fixed in Firefox 148.0.2EPSS 0.4%