Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2023-49061—An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects FirefoEPSS 0.3%CVE-2026-84126MEDIUMIncorrect boundary conditions in the Layout: Grid componentEPSS 0.3%CVE-2026-16386HIGHInformation disclosure due to uninitialized memory in the Graphics: WebGPU componentEPSS 0.3%CVE-2026-16384HIGHInformation disclosure due to uninitialized memory in the Graphics: WebGPU componentEPSS 0.3%CVE-2026-92046HIGHUse-after-free in the Graphics componentEPSS 0.3%CVE-2026-16385HIGHInformation disclosure due to uninitialized memory in the Graphics: WebGPU componentEPSS 0.3%CVE-2017-7761—The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combinEPSS 0.3%CVE-2025-14332HIGHMemory safety bugs fixed in Firefox 146 and Thunderbird 146EPSS 0.3%CVE-2025-6425MEDIUMThe WebCompat WebExtension shipped with Firefox exposed a persistent UUIDEPSS 0.3%CVE-2026-16370CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.3%CVE-2026-16380CRITICALMitigation bypass in the Networking componentEPSS 0.3%CVE-2026-16378HIGHOther issue in the DOM: Copy & Paste and Drag & Drop componentEPSS 0.3%CVE-2026-12299MEDIUMJIT miscompilation in the DOM: Core & HTML componentEPSS 0.3%CVE-2026-16364CRITICALIncorrect boundary conditions in the Audio/Video: Playback componentEPSS 0.3%CVE-2026-57963MEDIUMChat UI manipulation by injectionEPSS 0.3%CVE-2026-12298MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2024-0953MEDIUMWhen a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the cEPSS 0.3%CVE-2026-16410CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.3%CVE-2026-0890MEDIUMSpoofing issue in the DOM: Copy & Paste and Drag & Drop componentEPSS 0.3%CVE-2024-10474CRITICALFocus was incorrectly allowing internal links to utilize the app scheme used for deeplinking, which could result in links potentially circumEPSS 0.3%