Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2019-11742A same-origin policy violation occurs allowing the theft of cross-origin images through a combination of SVG filters and a <canvas> elEPSS 1.7%CVE-2019-9819A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable cEPSS 1.7%CVE-2021-43536Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL. This vulnerability affEPSS 1.7%CVE-2018-12382The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before EPSS 1.7%CVE-2020-12389The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only afEPSS 1.7%CVE-2018-5153If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bouEPSS 1.7%CVE-2018-18509A flaw during verification of certain S/MIME signatures causes emails to be shown in Thunderbird as having a valid digital signature, even iEPSS 1.7%CVE-2018-5165In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though thEPSS 1.7%CVE-2019-11710Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corEPSS 1.7%CVE-2021-38496During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentialEPSS 1.7%CVE-2018-5137A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this bEPSS 1.7%CVE-2018-5134WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictiEPSS 1.7%CVE-2020-15677By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to EPSS 1.7%CVE-2017-5385Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leadEPSS 1.7%CVE-2018-18497Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used withEPSS 1.6%CVE-2020-15667When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading tEPSS 1.6%CVE-2019-11740Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these EPSS 1.6%CVE-2017-5388A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short periEPSS 1.6%CVE-2019-9809If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resEPSS 1.6%CVE-2019-9820A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially explEPSS 1.6%