Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2024-5696HIGHBy manipulating the text in an `<input>` tag, an attacker could have caused corrupt memory leading to a potentially exploitable crash.EPSS 0.8%CVE-2020-15674—Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presumeEPSS 0.8%CVE-2021-38494—Mozilla developers reported memory safety bugs present in Firefox 91. Some of these bugs showed evidence of memory corruption and we presumeEPSS 0.8%CVE-2019-17000—An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin EPSS 0.8%CVE-2021-38507—The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual EPSS 0.8%CVE-2023-4584—Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2EPSS 0.8%CVE-2019-9817—Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a differEPSS 0.8%CVE-2017-7797—Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored hEPSS 0.8%CVE-2019-17001—A Content-Security-Policy that blocks in-line scripts could be bypassed using an object tag to execute JavaScript in the protected document EPSS 0.8%CVE-2023-28163MEDIUMWhen downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would hEPSS 0.8%CVE-2022-22742MEDIUMWhen inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable craEPSS 0.8%CVE-2023-6207—Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and EPSS 0.8%CVE-2021-23957—Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affecteEPSS 0.8%CVE-2022-45412HIGHWhen resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a sEPSS 0.8%CVE-2023-5721—It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient actiEPSS 0.8%CVE-2023-4058—Memory safety bugs present in Firefox 115. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.8%CVE-2019-9807—When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this EPSS 0.8%CVE-2020-12404—For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That tokEPSS 0.8%CVE-2022-34481HIGHIn the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replEPSS 0.8%CVE-2022-34478MEDIUMThe <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing theEPSS 0.8%