Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2021-29948—Signatures are written to disk before and read during verification, which might be subject to a race condition when a malicious local procesEPSS 0.3%CVE-2025-13020HIGHUse-after-free in the WebRTC: Audio/Video componentEPSS 0.3%CVE-2025-3035MEDIUMTab title disclosure across pages when using AI chatbotEPSS 0.3%CVE-2025-0510MEDIUMAddress of e-mail sender can be spoofed by malicious emailEPSS 0.3%CVE-2024-53975MEDIUMAccessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appeEPSS 0.3%CVE-2023-37210—A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoEPSS 0.3%CVE-2025-6434MEDIUMHTTPS-Only exception screen lacked anti-clickjacking delayEPSS 0.3%CVE-2024-0606MEDIUMAn attacker could execute unauthorized script on a legitimate site through UXSS using window.open() by opening a javascript URI leading to uEPSS 0.3%CVE-2026-92079CRITICALMitigation bypass in the Widget: Win32 componentEPSS 0.3%CVE-2017-7767—The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla WindowsEPSS 0.3%CVE-2026-92057CRITICALMitigation bypass in the Enterprise Policies componentEPSS 0.3%CVE-2026-6757MEDIUMInvalid pointer in the JavaScript: WebAssembly componentEPSS 0.3%CVE-2026-6762MEDIUMSpoofing issue in the DOM: Core & HTML componentEPSS 0.3%CVE-2024-9391MEDIUMA user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may EPSS 0.3%CVE-2017-7796—On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write a new log of that nEPSS 0.3%CVE-2026-16407CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.3%CVE-2026-16365HIGHPrivilege escalation in the DOM: Workers componentEPSS 0.3%CVE-2026-16379HIGHPrivilege escalation in the DOM: Content Processes componentEPSS 0.3%CVE-2024-26283HIGHAn attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom FEPSS 0.3%CVE-2026-74984MEDIUMRace condition in the JavaScript Engine componentEPSS 0.3%