Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2021-38509—Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be dEPSS 1.6%CVE-2017-5377—A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potentially exploitable craEPSS 1.6%CVE-2016-9073—WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affectsEPSS 1.6%CVE-2020-12396—Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corEPSS 1.6%CVE-2019-11711—When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomaiEPSS 1.6%CVE-2019-9793—A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disEPSS 1.6%CVE-2018-5152—WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to networEPSS 1.6%CVE-2017-7825—Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be usEPSS 1.6%CVE-2017-7847—Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.EPSS 1.6%CVE-2016-5299—A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for FirEPSS 1.6%CVE-2018-5136—A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policyEPSS 1.6%CVE-2018-5172—The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewinEPSS 1.6%CVE-2016-9061—A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keyEPSS 1.6%CVE-2020-26976—When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have inteEPSS 1.6%CVE-2018-12398—By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security EPSS 1.6%CVE-2018-5157—Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This couldEPSS 1.6%CVE-2021-43539—Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing EPSS 1.6%CVE-2020-12426—Mozilla developers and community members reported memory safety bugs present in Firefox 77. Some of these bugs showed evidence of memory corEPSS 1.6%CVE-2020-6823—A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the PromiEPSS 1.6%CVE-2020-12424—When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been tEPSS 1.6%