Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2025-49710CRITICALInteger overflow in OrderedHashTableEPSS 0.7%CVE-2022-22761HIGHWeb-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it wasEPSS 0.7%CVE-2022-22759CRITICALIf a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document tEPSS 0.7%CVE-2021-23982—Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as sEPSS 0.7%CVE-2023-29541HIGHFirefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commEPSS 0.7%CVE-2024-1551MEDIUMSet-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type responEPSS 0.7%CVE-2023-5173—In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a EPSS 0.7%CVE-2023-37207—A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL.EPSS 0.7%CVE-2025-0241HIGHMemory corruption when using JavaScript Text SegmentationEPSS 0.7%CVE-2024-9401CRITICALMemory safety bugs present in Firefox 130, Firefox ESR 115.15, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence EPSS 0.7%CVE-2024-0746MEDIUMA Linux user opening the print preview dialog could have caused the browser to crash. This vulnerability affects Firefox < 122, Firefox ESR EPSS 0.7%CVE-2023-32211—A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and ThundEPSS 0.7%CVE-2022-22748MEDIUMMalicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL prEPSS 0.7%CVE-2025-10533HIGHInteger overflow in the SVG componentEPSS 0.7%CVE-2023-25732HIGHWhen encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated pEPSS 0.7%CVE-2021-29965—A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to suggest passwords fEPSS 0.7%CVE-2023-29539—When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL chaEPSS 0.7%CVE-2021-29952—When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort maEPSS 0.7%CVE-2021-23983—By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memoEPSS 0.7%CVE-2024-5690MEDIUMBy monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's EPSS 0.7%