Vulnerabilidades em Mozilla

2.105 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2025-6703LOWtransport/fc.rs: panic attempting to send MAX_DATA with value larger max varintEPSS 0.2%CVE-2025-9183MEDIUMSpoofing issue in the Address Bar componentEPSS 0.2%CVE-2026-92067HIGHUse-after-free in the Widget: Gtk componentEPSS 0.2%CVE-2026-16400HIGHInformation disclosure in the DOM: Security componentEPSS 0.2%CVE-2026-12302MEDIUMMitigation bypass in the DOM: Security componentEPSS 0.2%CVE-2022-34471MEDIUMWhen downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifEPSS 0.2%CVE-2026-92056HIGHUse-after-free in the Graphics: Text componentEPSS 0.2%CVE-2026-92060HIGHUse-after-free in the Internationalization componentEPSS 0.2%CVE-2026-92049HIGHUse-after-free in the Widget: Win32 componentEPSS 0.2%CVE-2025-1940HIGHAndroid Intent confirmation prompt tapjacking using Select optionsEPSS 0.2%CVE-2025-5263MEDIUMError handling for script execution was incorrectly isolated from web contentEPSS 0.2%CVE-2025-9180HIGHSame-origin policy bypass in the Graphics: Canvas2D componentEPSS 0.2%CVE-2026-2919MEDIUMAttacker-controlled content shown under spoofed domains in Focus for iOS via stalled navigation and iframe redirectEPSS 0.2%CVE-2026-74975MEDIUMSpoofing issue in the Downloads component in Firefox for AndroidEPSS 0.2%CVE-2026-92030MEDIUMMitigation bypass in the DOM: Copy & Paste and Drag & Drop componentEPSS 0.2%CVE-2026-12316CRITICALMitigation bypass in the DOM: Security componentEPSS 0.2%CVE-2024-3857HIGHThe JIT created incorrect code for arguments in certain cases. This led to potential use-after-free crashes during garbage collection. This EPSS 0.2%CVE-2022-22736HIGHIf Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directoryEPSS 0.2%CVE-2024-38313MEDIUMIn certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual websiteEPSS 0.2%CVE-2025-8038CRITICALCSP frame-src was not correctly enforced for pathsEPSS 0.2%