Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2020-26968—Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corrEPSS 1.5%CVE-2017-7832—The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofEPSS 1.5%CVE-2017-5451—A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by scriptEPSS 1.5%CVE-2020-6793—When processing an email message with an ill-formed envelope, Thunderbird could read data from a random memory location. This vulnerability EPSS 1.5%CVE-2020-15656—JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various prEPSS 1.5%CVE-2019-9812—Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firEPSS 1.5%CVE-2019-11694—A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making aEPSS 1.5%CVE-2020-6828—A malicious Android application could craft an Intent that would have been processed by Firefox for Android and potentially result in a fileEPSS 1.5%CVE-2021-23985—If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugEPSS 1.5%CVE-2020-6821—When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification rEPSS 1.5%CVE-2019-11756—Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnEPSS 1.5%CVE-2017-5384—Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more informEPSS 1.5%CVE-2019-11715—Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards onEPSS 1.5%CVE-2016-5292—During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50.EPSS 1.5%CVE-2017-7804—The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability tEPSS 1.5%CVE-2020-6805—When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentiaEPSS 1.5%CVE-2020-6809—When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web ExteEPSS 1.5%CVE-2021-29955—A transient execution vulnerability, named Floating Point Value Injection (FPVI) allowed an attacker to leak arbitrary memory addresses and EPSS 1.5%CVE-2020-6797—By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer.EPSS 1.5%CVE-2021-23961—Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosEPSS 1.5%