Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2021-43546—It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects ThunderbiEPSS 1.4%CVE-2019-17007—In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of serviceEPSS 1.4%CVE-2020-15653—An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues forEPSS 1.4%CVE-2019-11721—The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks aEPSS 1.4%CVE-2021-43530—A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QEPSS 1.4%CVE-2017-7755—The Firefox installer on Windows can be made to load malicious DLL files stored in the same directory as the installer when it is run. This EPSS 1.4%CVE-2021-29984—Instruction reordering resulted in a sequence of instructions that would cause an object to be incorrectly considered during garbage collectEPSS 1.4%CVE-2021-29988—Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a pEPSS 1.4%CVE-2020-15664—By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTriggerEPSS 1.4%CVE-2018-18503—When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatcEPSS 1.4%CVE-2021-23999—If a Blob URL was loaded through some unusual user interaction, it could have been loaded by the System Principal and granted additional priEPSS 1.4%CVE-2019-11700—A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution whEPSS 1.4%CVE-2019-11760—A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some iEPSS 1.4%CVE-2025-1015MEDIUMUnsanitized address book fieldsEPSS 1.4%CVE-2021-23973—When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may EPSS 1.4%CVE-2021-29967—Mozilla developers reported memory safety bugs present in Firefox 88 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corEPSS 1.4%CVE-2019-11702—A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with InEPSS 1.4%CVE-2021-21354HIGHOpen redirect in pollbotEPSS 1.4%CVE-2020-26958—Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. TEPSS 1.4%CVE-2017-7822—The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NIST Special PublicatiEPSS 1.4%