Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2018-5167—The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, cliEPSS 1.4%CVE-2017-5426—On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox failsEPSS 1.4%CVE-2018-12388—Mozilla developers and community members reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corEPSS 1.4%CVE-2021-29970—A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This bug could only be tEPSS 1.4%CVE-2020-6826—Mozilla developers Tyson Smith, Bob Clary, and Alexandru Michis reported memory safety bugs present in Firefox 74. Some of these bugs showedEPSS 1.4%CVE-2020-12391—Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scriEPSS 1.4%CVE-2017-5458—When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users toEPSS 1.4%CVE-2020-15654—When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interfEPSS 1.4%CVE-2017-7774—Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.EPSS 1.4%CVE-2017-7773—Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.EPSS 1.4%CVE-2017-7772—Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.EPSS 1.4%CVE-2021-23987—Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed eEPSS 1.4%CVE-2020-35111—When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-sourceEPSS 1.4%CVE-2019-11733—When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It wEPSS 1.4%CVE-2023-6861—The `nsWindow::PickerOpen(void)` method was susceptible to a heap buffer overflow when running in headless mode. This vulnerability affects EPSS 1.4%CVE-2020-6801—Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.4%CVE-2021-29980—Uninitialized memory in a canvas object could have caused an incorrect free() leading to memory corruption and a potentially exploitable craEPSS 1.4%CVE-2023-6209—Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override thEPSS 1.4%CVE-2017-7799—JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usageEPSS 1.4%CVE-2020-12387—A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitableEPSS 1.4%