Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2021-23964—Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6. Some of these bugs showed evidence of memory corrEPSS 1.4%CVE-2020-6815—Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruptEPSS 1.4%CVE-2017-7765—The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the MarkEPSS 1.4%CVE-2017-5031—A use after free in ANGLE in Google Chrome prior to 57.0.2987.98 for Windows allowed a remote attacker to perform an out of bounds memory reEPSS 1.4%CVE-2019-9805—A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential EPSS 1.4%CVE-2020-26966—Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting EPSS 1.4%CVE-2019-11716—Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropeEPSS 1.4%CVE-2019-11698—If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped EPSS 1.4%CVE-2018-5169—If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to EPSS 1.4%CVE-2021-43543—Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vuEPSS 1.4%CVE-2020-12405—When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vuEPSS 1.4%CVE-2020-12416—A VideoStreamEncoder may have been freed in a race condition with VideoBroadcaster::AddOrUpdateSink, resulting in a use-after-free, memory cEPSS 1.4%CVE-2020-15684—Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.3%CVE-2022-22744HIGHThe constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to coEPSS 1.3%CVE-2022-40962HIGHMozilla developers Nika Layzell, Timothy Nikkel, Sebastian Hengst, Andreas Pehrson, and the Mozilla Fuzzing Team reported memory safety bugsEPSS 1.3%CVE-2019-17023—After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition inEPSS 1.3%CVE-2021-4140CRITICALIt was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 9EPSS 1.3%CVE-2019-11757—When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. ThiEPSS 1.3%CVE-2020-6792—When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affeEPSS 1.3%CVE-2016-9072—When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note:EPSS 1.3%