Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2023-6212Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruptionEPSS 0.8%CVE-2021-29960Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web EPSS 0.8%CVE-2024-11693CRITICALThe executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systemEPSS 0.8%CVE-2022-38476HIGHA data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this EPSS 0.8%CVE-2021-29968When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. OtherEPSS 0.8%CVE-2020-26955When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operaEPSS 0.8%CVE-2021-38499Mozilla developers reported memory safety bugs present in Firefox 92. Some of these bugs showed evidence of memory corruption and we presumeEPSS 0.8%CVE-2023-5388MEDIUMNSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recovEPSS 0.8%CVE-2023-4576Integer Overflow in RecordedSourceSurfaceCreationEPSS 0.8%CVE-2023-5172CRITICALA hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and EPSS 0.8%CVE-2023-0767HIGHAn attacker could construct a PKCS 12 cert bundle in such a way that could allow for arbitrary memory writes via PKCS 12 Safe Bag attributesEPSS 0.8%CVE-2021-23997Due to unexpected data type conversions, a use-after-free could have occurred when interacting with the font cache. We presume that with enoEPSS 0.8%CVE-2021-29964A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds reEPSS 0.8%CVE-2022-31737CRITICALA malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. ThiEPSS 0.8%CVE-2024-3863CRITICALThe executable file warning was not presented when downloading .xrm-ms files. *Note: This issue only affected Windows operating systems. OEPSS 0.8%CVE-2021-29973Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interEPSS 0.8%CVE-2025-0238MEDIUMUse-after-free when breaking lines in textEPSS 0.8%CVE-2024-10466HIGHBy sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive.EPSS 0.8%CVE-2021-29956OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on the user's local diEPSS 0.8%CVE-2019-11723A vulnerability exists during the installation of add-ons where the initial fetch ignored the origin attributes of the browsing context. ThiEPSS 0.8%