Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-6763MEDIUMMitigation bypass in the File Handling componentEPSS 0.3%CVE-2026-92035CRITICALSandbox escape due to incorrect boundary conditions in the Graphics componentEPSS 0.3%CVE-2026-92045CRITICALSandbox escape due to incorrect boundary conditions in the WebRTC componentEPSS 0.3%CVE-2026-84121CRITICALSandbox escape due to use-after-free in the DOM: Security componentEPSS 0.3%CVE-2025-1933HIGHJIT corruption of WASM i32 return values on 64-bit CPUsEPSS 0.3%CVE-2026-84119CRITICALSandbox escape due to use-after-free in the DOM: Navigation componentEPSS 0.3%CVE-2022-36316MEDIUMWhen using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the targEPSS 0.3%CVE-2025-4087MEDIUMUnsafe attribute access during XPath parsingEPSS 0.3%CVE-2021-29949—When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filenamEPSS 0.3%CVE-2026-16390CRITICALMitigation bypass in the Enterprise Policies componentEPSS 0.3%CVE-2023-29540—Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes witEPSS 0.3%CVE-2026-16361CRITICALMemory safety bugs fixed in Thunderbird ESR 140.13EPSS 0.3%CVE-2025-12380CRITICALUse-after-free in WebGPU internals triggered from a compromised child processEPSS 0.3%CVE-2025-14860CRITICALUse-after-free in the Disability Access APIs componentEPSS 0.3%CVE-2025-3608MEDIUMRace condition in nsHttpTransaction could lead to memory corruptionEPSS 0.3%CVE-2025-3523MEDIUMUser Interface (UI) Misrepresentation of attachment URLEPSS 0.3%CVE-2026-12329MEDIUMMemory safety bug fixed in Thunderbird ESR 140.12EPSS 0.3%CVE-2024-26281MEDIUMUpon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin siteEPSS 0.3%CVE-2025-10535HIGHInformation disclosure, mitigation bypass in the Privacy component in Firefox for AndroidEPSS 0.3%CVE-2025-10532MEDIUMIncorrect boundary conditions in the JavaScript: GC componentEPSS 0.3%