Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2022-46874HIGHA file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place.EPSS 0.9%CVE-2021-23977—Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data fromEPSS 0.9%CVE-2019-17018—When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This EPSS 0.9%CVE-2022-31747CRITICALMozilla developers Andrew McCreight, Nicolas B. Pierron, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 100 andEPSS 0.9%CVE-2021-23958—The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. ThiEPSS 0.9%CVE-2021-38491—Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox EPSS 0.9%CVE-2023-5727—The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on aEPSS 0.9%CVE-2022-22751HIGHMozilla developers Calixte Denizet, Kershaw Chang, Christian Holler, Jason Kratzer, Gabriele Svelto, Tyson Smith, Simon Giesecke, and Steve EPSS 0.9%CVE-2021-29947—Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corEPSS 0.9%CVE-2023-6205—It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash.EPSS 0.9%CVE-2024-1553HIGHMemory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruptionEPSS 0.9%CVE-2021-43540—WebExtensions with the correct permissions were able to create and install ServiceWorkers for third-party websites that would not have been EPSS 0.9%CVE-2020-26975—When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been spEPSS 0.9%CVE-2024-5702HIGHMemory corruption in the networking stack could have led to a potentially exploitable crash. This vulnerability affects Firefox < 125, FirefEPSS 0.9%CVE-2026-10702MEDIUMJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.9%CVE-2022-29909HIGHDocuments in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the exiEPSS 0.9%CVE-2025-3028MEDIUMUse-after-free triggered by XSLTProcessorEPSS 0.9%CVE-2024-3864HIGHMemory safety bug present in Firefox 124, Firefox ESR 115.9, and Thunderbird 115.9. This bug showed evidence of memory corruption and we preEPSS 0.9%CVE-2021-29950—Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task. If the task runs into a failure,EPSS 0.9%CVE-2023-6873—Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.9%