Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2024-6605HIGHFirefox Android missed activation delay to prevent tapjackingEPSS 0.4%CVE-2025-6429MEDIUMIncorrect parsing of URLs could have allowed embedding of youtube.comEPSS 0.4%CVE-2025-13024CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2025-13026CRITICALSandbox escape due to incorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-92075CRITICALMitigation bypass in the Networking componentEPSS 0.4%CVE-2026-3889MEDIUMSpoofing issue in ThunderbirdEPSS 0.4%CVE-2025-11719CRITICALUse-after-free caused by the native messaging web extension API on WindowsEPSS 0.4%CVE-2026-92041CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.4%CVE-2026-92038CRITICALMitigation bypass in the Remote Settings Client componentEPSS 0.4%CVE-2020-15657—Firefox could be made to load attacker-supplied DLL files from the installation directory. This required an attacker that is already capableEPSS 0.4%CVE-2025-10528HIGHSandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D componentEPSS 0.4%CVE-2026-0888MEDIUMInformation disclosure in the XML componentEPSS 0.4%CVE-2025-8035HIGHMemory safety bugs fixed in Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.4%CVE-2025-10534HIGHSpoofing issue in the Site Permissions componentEPSS 0.4%CVE-2026-4684HIGHRace condition, use-after-free in the Graphics: WebRender componentEPSS 0.4%CVE-2025-2830MEDIUMInformation Disclosure of /tmp directory listingEPSS 0.4%CVE-2025-6432HIGHDNS Requests leaked outside of a configured SOCKS proxyEPSS 0.4%CVE-2026-92006HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.4%CVE-2026-92018CRITICALSandbox escape in the DOM: Core & HTML componentEPSS 0.4%CVE-2025-26696HIGHCrafted email message incorrectly shown as being encryptedEPSS 0.3%