Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2019-11742—A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> elEPSS 1.7%CVE-2019-9819—A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable cEPSS 1.7%CVE-2021-43536—Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affEPSS 1.7%CVE-2018-12382—The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before EPSS 1.7%CVE-2020-12389—The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only afEPSS 1.7%CVE-2018-5153—If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bouEPSS 1.7%CVE-2018-18509—A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even iEPSS 1.7%CVE-2018-5165—In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though thEPSS 1.7%CVE-2019-11710—Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corEPSS 1.7%CVE-2021-38496—During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentialEPSS 1.7%CVE-2018-5137—A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this bEPSS 1.7%CVE-2018-5134—WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictiEPSS 1.7%CVE-2020-15677—By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to EPSS 1.7%CVE-2017-5385—Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leadEPSS 1.7%CVE-2018-18497—Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used withEPSS 1.6%CVE-2020-15667—When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading tEPSS 1.6%CVE-2019-11740—Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these EPSS 1.6%CVE-2017-5388—A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short periEPSS 1.6%CVE-2019-9809—If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resEPSS 1.6%CVE-2019-9820—A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially explEPSS 1.6%