Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2024-26282HIGHUsing an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affEPSS 0.3%CVE-2024-0749MEDIUMA phishing site could have repurposed an `about:` dialog to show phishing content with an incorrect origin in the address bar. This vulnerabEPSS 0.3%CVE-2026-16402CRITICALInteger overflow in the Graphics: ImageLib componentEPSS 0.3%CVE-2026-4728MEDIUMSpoofing issue in the Privacy: Anti-Tracking componentEPSS 0.3%CVE-2017-7836—The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attacker could replace. TEPSS 0.3%CVE-2026-84131HIGHPrivilege escalation due to invalid pointer in the Graphics componentEPSS 0.3%CVE-2025-11714HIGHMemory safety bugs fixed in Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2021-29963—Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affects Firefox for AndrEPSS 0.3%CVE-2023-4104MEDIUMAn invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitraEPSS 0.3%CVE-2026-92016HIGHUse-after-free in the Disability Access APIs componentEPSS 0.3%CVE-2026-92026HIGHUse-after-free in the Networking componentEPSS 0.3%CVE-2019-17009—When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to loEPSS 0.3%CVE-2025-13027HIGHMemory safety bugs fixed in Firefox 145 and Thunderbird 145EPSS 0.3%CVE-2017-5414—The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead EPSS 0.3%CVE-2026-0887MEDIUMClickjacking issue, information disclosure in the PDF Viewer componentEPSS 0.3%CVE-2024-8394MEDIUMWhen aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitabEPSS 0.3%CVE-2025-8029HIGHjavascript: URLs executed on object and embed tagsEPSS 0.3%CVE-2025-8030HIGHPotential user-assisted code execution in “Copy as cURL” commandEPSS 0.3%CVE-2024-11708MEDIUMMissing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affecEPSS 0.3%CVE-2021-43531—When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web ExEPSS 0.3%