Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2025-10527HIGHSandbox escape due to use-after-free in the Graphics: Canvas2D componentEPSS 0.3%CVE-2026-92015HIGHPrivilege escalation in the WebExtensions componentEPSS 0.3%CVE-2026-92009HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92013HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92008HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92011HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92007HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92012HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92020HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: WebRender componentEPSS 0.3%CVE-2025-13025HIGHIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.3%CVE-2026-92010HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-8951MEDIUMSpoofing issue in the Toolbar component in Firefox for AndroidEPSS 0.3%CVE-2020-12394—A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different oEPSS 0.3%CVE-2026-74980MEDIUMClickjacking issue in the Downloads component in Firefox for AndroidEPSS 0.3%CVE-2026-74951MEDIUMClickjacking issue in Firefox for AndroidEPSS 0.3%CVE-2024-7523MEDIUMA select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. EPSS 0.3%CVE-2024-4765HIGHWeb application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's maEPSS 0.3%CVE-2023-0163HIGHPrototype Pollution in convictEPSS 0.3%CVE-2026-14899HIGHOff-by-one out of bounds read in MIME header parser for forwardingEPSS 0.3%CVE-2025-11712MEDIUMAn OBJECT tag type attribute overrode browser behavior on web resources without a content-typeEPSS 0.3%