Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2020-26977By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar dispEPSS 0.9%CVE-2020-26967When listening for page changes with a Mutation Observer, a malicious web page could confuse Firefox Screenshots into interacting with elemeEPSS 0.9%CVE-2022-26381HIGHAn attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vuEPSS 0.8%CVE-2020-15685HIGHDuring the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted sEPSS 0.8%CVE-2021-4138Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified hostname.EPSS 0.8%CVE-2019-11697If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the installEPSS 0.8%CVE-2020-26963Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by introducing rate-limitEPSS 0.8%CVE-2019-9821A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exEPSS 0.8%CVE-2020-15661A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for thEPSS 0.8%CVE-2019-11765A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown.EPSS 0.8%CVE-2019-11699A malicious page can briefly cause the wrong name to be highlighted as the domain name in the addressbar during page navigations. This couldEPSS 0.8%CVE-2023-5175CRITICALDuring process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepEPSS 0.8%CVE-2021-29974When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to oEPSS 0.8%CVE-2021-29959When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website fromEPSS 0.8%CVE-2017-7808A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths insteadEPSS 0.8%CVE-2019-11696Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even thoughEPSS 0.8%CVE-2024-0750HIGHA bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vEPSS 0.8%CVE-2023-6204On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the EPSS 0.8%CVE-2022-42928HIGHCertain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corrEPSS 0.8%CVE-2013-1689Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.EPSS 0.8%