Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2020-6807—When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the strEPSS 1.5%CVE-2019-11764—Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed eEPSS 1.5%CVE-2017-7838—Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punyEPSS 1.5%CVE-2018-5110—If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invEPSS 1.5%CVE-2017-7833—Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-Latin character withEPSS 1.5%CVE-2018-5121—Low descenders on some Tibetan characters in several fonts on OS X are clipped when rendered in the addressbar. When used as part of an InteEPSS 1.5%CVE-2017-5463—Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the conEPSS 1.5%CVE-2017-7837—SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox <EPSS 1.5%CVE-2017-7823—The content security policy (CSP) "sandbox" directive did not create a unique origin for the document, causing it to behave as if the "allowEPSS 1.5%CVE-2018-5132—The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allEPSS 1.5%CVE-2021-38498—During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potEPSS 1.5%CVE-2020-6829—When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about theEPSS 1.5%CVE-2023-5730—Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruptionEPSS 1.5%CVE-2021-38506—Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to EPSS 1.5%CVE-2018-5175—A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target EPSS 1.5%CVE-2021-29985—A use-after-free vulnerability in media channels could have led to memory corruption and a potentially exploitable crash. This vulnerabilityEPSS 1.5%CVE-2019-11744—Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is poEPSS 1.5%CVE-2019-11738—If a Content Security Policy (CSP) directive is defined that uses a hash-based source that takes the empty string as input, execution of anyEPSS 1.4%CVE-2018-12371—An integer overflow vulnerability in the Skia library when allocating memory for edge builders on some systems with at least 16 GB of RAM. TEPSS 1.4%CVE-2018-5176—The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file containsEPSS 1.4%