Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2025-8032HIGHXSLT documents could bypass CSPEPSS 0.3%CVE-2024-31393MEDIUMDragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerabilitEPSS 0.3%CVE-2025-11715HIGHMemory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2025-10537HIGHMemory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143EPSS 0.3%CVE-2026-92031MEDIUMInformation disclosure in the Graphics: ImageLib componentEPSS 0.3%CVE-2025-5266MEDIUMScript element events leaked cross-origin resource statusEPSS 0.3%CVE-2017-7768—The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincEPSS 0.3%CVE-2023-29549MEDIUMUnder certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnEPSS 0.3%CVE-2025-4090MEDIUMLeaked library paths in Thunderbird for AndroidEPSS 0.3%CVE-2025-5272HIGHMemory safety bugs fixed in Firefox 139 and Thunderbird 139EPSS 0.3%CVE-2016-5295—This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke EPSS 0.3%CVE-2024-9395MEDIUMA specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *EPSS 0.3%CVE-2025-1013MEDIUMPotential opening of private browsing tabs in normal browsing windowsEPSS 0.3%CVE-2024-26284MEDIUMUtilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a EPSS 0.3%CVE-2024-10460MEDIUMThe origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects EPSS 0.3%CVE-2025-8040HIGHMemory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.3%CVE-2020-12401—During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resultinEPSS 0.3%CVE-2026-84639CRITICALUninitialized memory in MIME parsingEPSS 0.3%CVE-2026-16374HIGHInformation disclosure in the Framework component in DevToolsEPSS 0.3%CVE-2026-16391HIGHInformation disclosure in the Storage: IndexedDB componentEPSS 0.3%