Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2020-26973Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer byEPSS 1.6%CVE-2019-11692A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potenEPSS 1.6%CVE-2020-6812The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites wiEPSS 1.6%CVE-2023-5724HIGHDrivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability afEPSS 1.6%CVE-2017-7813Inside the JavaScript parser, a cast of an integer to a narrower type can result in data read from outside the buffer being parsed. This usuEPSS 1.6%CVE-2021-43545Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, FiEPSS 1.6%CVE-2018-5164Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME typeEPSS 1.6%CVE-2020-15676Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed aEPSS 1.6%CVE-2020-6796A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. EPSS 1.6%CVE-2017-7831A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism oEPSS 1.6%CVE-2018-5141A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user intEPSS 1.6%CVE-2020-12390Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks. This vulnerability affects Firefox < 76.EPSS 1.6%CVE-2018-18512A use-after-free vulnerability can occur while playing a sound notification in Thunderbird. The memory storing the sound data is immediatelyEPSS 1.6%CVE-2018-5111When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a differEPSS 1.6%CVE-2021-43541When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerabilEPSS 1.6%CVE-2020-12425Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential infoEPSS 1.6%CVE-2018-12400In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows EPSS 1.6%CVE-2018-12399When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registeEPSS 1.6%CVE-2020-26960If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potenEPSS 1.6%CVE-2019-11691A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called aEPSS 1.6%