Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2020-6810—After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the broEPSS 1.0%CVE-2019-9802—If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded daEPSS 1.0%CVE-2019-11748—WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party cEPSS 1.0%CVE-2023-5171—During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes,EPSS 1.0%CVE-2018-5116—WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. MaEPSS 1.0%CVE-2021-29966—Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2021-29971—If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port EPSS 1.0%CVE-2020-12406—Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enEPSS 1.0%CVE-2020-6794—If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessEPSS 1.0%CVE-2018-18499—A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a reEPSS 1.0%CVE-2021-4129CRITICALMozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano rEPSS 1.0%CVE-2021-23972—One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this EPSS 1.0%CVE-2020-15675—When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. ThiEPSS 1.0%CVE-2021-29981—An issue present in lowering/register allocation could have led to obscure but deterministic register confusion failures in JITted code thatEPSS 1.0%CVE-2021-23975—The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this EPSS 1.0%CVE-2020-12393—The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the webEPSS 1.0%CVE-2016-9064—Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who couEPSS 1.0%CVE-2021-29990—Mozilla developers and community members reported memory safety bugs present in Firefox 90. Some of these bugs showed evidence of memory corEPSS 1.0%CVE-2023-5169—A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a poteEPSS 1.0%CVE-2021-29977—Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%