Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2026-84640HIGHOne byte overflow read in mail parserEPSS 0.3%CVE-2026-9309MEDIUMArbitrary JavaScript execution in internal pages via Reader View JSON-LD injectionEPSS 0.3%CVE-2026-9308MEDIUMArbitrary JavaScript execution in Reader View due to wrong HTML replacement orderEPSS 0.3%CVE-2026-92053HIGHPrivilege escalation in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2025-13015LOWSpoofing issue in FirefoxEPSS 0.3%CVE-2026-12307MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2026-12308MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2026-12306MEDIUMMemory safety bug fixed in Firefox 152EPSS 0.3%CVE-2025-27424MEDIUMFirefox Mobile iOS Address Bar Spoof Using Server-Side Redirect to non-http SchemeEPSS 0.3%CVE-2026-92054HIGHPrivilege escalation in the Memory componentEPSS 0.3%CVE-2026-84127MEDIUMInformation disclosure in the WebExtensions component in Firefox for AndroidEPSS 0.3%CVE-2026-6774MEDIUMMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2026-81267MEDIUMStalled popup navigation could allow address bar origin spoofing in Firefox for iOSEPSS 0.3%CVE-2025-13019HIGHSame-origin policy bypass in the DOM: Workers componentEPSS 0.3%CVE-2025-13018HIGHMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2025-13017HIGHSame-origin policy bypass in the DOM: Notifications componentEPSS 0.3%CVE-2026-9078MEDIUMFirefox iOS RTL Domain Rendering Issue in Link PreviewEPSS 0.3%CVE-2026-16405HIGHInformation disclosure in the Networking: WebSockets componentEPSS 0.3%CVE-2026-92052HIGHPrivilege escalation due to uninitialized memory in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92043HIGHPrivilege escalation due to incorrect boundary conditions in the Audio/Video componentEPSS 0.3%