Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2018-5118The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. AnEPSS 1.6%CVE-2018-5114If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that EPSS 1.6%CVE-2018-5119The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This EPSS 1.6%CVE-2020-35113Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corrEPSS 1.6%CVE-2018-18494A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirecEPSS 1.5%CVE-2017-5466If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will ruEPSS 1.5%CVE-2017-7842If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of oEPSS 1.5%CVE-2023-6858HIGHFirefox was susceptible to a heap buffer overflow in `nsTextFragment` due to insufficient OOM handling. This vulnerability affects Firefox EEPSS 1.5%CVE-2017-7834A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for bypasses of the policEPSS 1.5%CVE-2018-5185Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and ThEPSS 1.5%CVE-2020-6799Command line arguments could have been injected during Firefox invocation as a shell handler for certain unsupported file types. This requirEPSS 1.5%CVE-2021-23978Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corrEPSS 1.5%CVE-2018-5135WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts wherEPSS 1.5%CVE-2021-38508By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validitEPSS 1.5%CVE-2019-17011Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-freeEPSS 1.5%CVE-2017-7835Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correctly applied for resources that redirect fEPSS 1.5%CVE-2018-5133If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not saniEPSS 1.5%CVE-2020-15655A redirected HTTP request which is observed or modified through a web extension could bypass existing CORS checks, leading to potential discEPSS 1.5%CVE-2017-5382Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internEPSS 1.5%CVE-2020-26974When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulteEPSS 1.5%