Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2022-45421HIGHMozilla developers Andrew McCreight and Gabriele Svelto reported memory safety bugs present in Thunderbird 102.4. Some of these bugs showed EPSS 0.7%CVE-2023-29536—An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertioEPSS 0.7%CVE-2022-0566HIGHIt may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when procEPSS 0.7%CVE-2022-34476CRITICALASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulneraEPSS 0.7%CVE-2022-45408MEDIUMThrough a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification pEPSS 0.7%CVE-2024-2616LOWTo harden ICU against exploitation, the behavior for out-of-memory conditions was changed to crash instead of attempt to continue. This vulnEPSS 0.7%CVE-2024-11691HIGHCertain WebGL operations on Apple silicon M series devices could have lead to an out-of-bounds write and memory corruption due to a flaw in EPSS 0.7%CVE-2022-46877MEDIUMBy confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofiEPSS 0.7%CVE-2020-26962—Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have beEPSS 0.7%CVE-2022-28289HIGHMozilla developers and community members Nika Layzell, Andrew McCreight, Gabriele Svelto, and the Mozilla Fuzzing Team reported memory safetEPSS 0.7%CVE-2011-2670—Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style SheetsEPSS 0.7%CVE-2022-45403MEDIUMService Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media cEPSS 0.7%CVE-2023-29548MEDIUMA wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, FoEPSS 0.7%CVE-2022-36319HIGHWhen combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vuEPSS 0.7%CVE-2023-5723—An attacker with temporary script access to a site could have set a cookie containing invalid characters using `document.cookie` that could EPSS 0.7%CVE-2024-10463HIGHVideo frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, FirefEPSS 0.7%CVE-2023-25751—Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could leaEPSS 0.7%CVE-2022-38473HIGHA cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). ThisEPSS 0.7%CVE-2024-11698CRITICALA flaw in handling fullscreen transitions may have inadvertently caused the application to become stuck in fullscreen mode when a modal dialEPSS 0.7%CVE-2026-4693HIGHIncorrect boundary conditions in the Audio/Video: Playback componentEPSS 0.7%