Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2019-11747The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site.EPSS 1.2%CVE-2017-7820The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web EPSS 1.2%CVE-2021-23954Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruptiEPSS 1.2%CVE-2017-7771Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.EPSS 1.2%CVE-2023-5728HIGHDuring garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable cEPSS 1.2%CVE-2021-23995When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this cEPSS 1.2%CVE-2018-18496When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjackingEPSS 1.2%CVE-2019-11735Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed eviEPSS 1.2%CVE-2020-12409When using certain blank characters in a URL, they where incorrectly rendered as spaces instead of an encoded URL. This vulnerability affectEPSS 1.2%CVE-2020-12411Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.2%CVE-2018-5116WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. MaEPSS 1.2%CVE-2020-26961When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming fEPSS 1.2%CVE-2020-26952Incorrect bookkeeping of functions inlined during JIT compilation could have led to memory corruption and a potentially exploitable crash whEPSS 1.2%CVE-2017-7817A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be dispEPSS 1.2%CVE-2017-7815On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domaEPSS 1.2%CVE-2021-43538By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received full screEPSS 1.2%CVE-2021-38492When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and exEPSS 1.2%CVE-2018-5108A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed betweeEPSS 1.2%CVE-2019-11725When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resEPSS 1.1%CVE-2019-17020If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not beEPSS 1.1%