Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2019-11758—Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed eEPSS 1.3%CVE-2020-6822—On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in <code>GMPDecodeData</code>. It is EPSS 1.3%CVE-2018-18513—A crash can occur when processing a crafted S/MIME message or an XPI package containing a crafted signature. This can be used as a denial-ofEPSS 1.3%CVE-2020-26978—Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as sEPSS 1.3%CVE-2016-9902—The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. TEPSS 1.3%CVE-2018-12402—The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loEPSS 1.3%CVE-2019-9801—Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matchiEPSS 1.3%CVE-2021-23968—If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation reEPSS 1.3%CVE-2020-6795—When processing a message that contains multiple S/MIME signatures, a bug in the MIME processing code caused a null pointer dereference, leaEPSS 1.3%CVE-2021-29946—Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when usedEPSS 1.3%CVE-2018-5140—Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This coulEPSS 1.3%CVE-2020-26959—During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruEPSS 1.3%CVE-2019-11734—Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corEPSS 1.3%CVE-2020-26972—The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting tEPSS 1.3%CVE-2020-26953—It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishEPSS 1.3%CVE-2021-23960—Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. ThisEPSS 1.3%CVE-2024-0743HIGHAn unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122,EPSS 1.3%CVE-2022-40959MEDIUMDuring iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissionEPSS 1.3%CVE-2017-5420—A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an aEPSS 1.3%CVE-2019-9814—Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corEPSS 1.3%