Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2023-32216Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bEPSS 0.8%CVE-2023-34417CRITICALMemory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.8%CVE-2022-45409HIGHThe garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been calEPSS 0.8%CVE-2023-6208When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage notEPSS 0.8%CVE-2020-12412By navigating a tab using the history API, an attacker could cause the address bar to display the incorrect domain (with the https:// schemeEPSS 0.8%CVE-2023-25734HIGHAfter downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to EPSS 0.8%CVE-2022-3033HIGHIf a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>htEPSS 0.8%CVE-2023-4585HIGHMemory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2EPSS 0.8%CVE-2026-4690CRITICALSandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM componentEPSS 0.8%CVE-2017-5394A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScEPSS 0.8%CVE-2024-5699CRITICALIn violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be EPSS 0.8%CVE-2022-46872HIGHAn attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC mesEPSS 0.8%CVE-2026-4694HIGHIncorrect boundary conditions, integer overflow in the Graphics componentEPSS 0.8%CVE-2023-4053Full screen notification obscured by external programEPSS 0.8%CVE-2023-25741MEDIUMWhen dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused EPSS 0.8%CVE-2024-3302LOWThere was no limit to the number of HTTP/2 CONTINUATION frames that would be processed. A server could abuse this to create an Out of MemoryEPSS 0.8%CVE-2024-11697HIGHWhen handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialogEPSS 0.8%CVE-2020-6827When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into disEPSS 0.8%CVE-2023-32209A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.EPSS 0.8%CVE-2013-4227Cross-site request forgery (CSRF) vulnerability in the persona_xsrf_token function in persona.module in the Mozilla Persona module 7.x-1.x bEPSS 0.8%