Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2026-4685HIGHIncorrect boundary conditions in the Graphics: Canvas2D componentEPSS 0.7%CVE-2026-4697HIGHIncorrect boundary conditions in the Audio/Video: Web Codecs componentEPSS 0.7%CVE-2026-4693HIGHIncorrect boundary conditions in the Audio/Video: Playback componentEPSS 0.7%CVE-2026-4699HIGHIncorrect boundary conditions in the Layout: Text and Fonts componentEPSS 0.7%CVE-2020-15665—Firefox did not reset the address bar after the beforeunload dialog was shown if the user chose to remain on the page. This could have resulEPSS 0.7%CVE-2023-25736CRITICALAn invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.EPSS 0.7%CVE-2023-4583HIGHBrowsing Context potentially not cleared when closing Private WindowEPSS 0.7%CVE-2013-5594—Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml bindingEPSS 0.7%CVE-2023-6867—The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission proEPSS 0.7%CVE-2024-11699HIGHMemory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruptionEPSS 0.7%CVE-2024-1936HIGHThe encrypted subject of an email message could be incorrectly and permanently assigned to an arbitrary other email message in Thunderbird'sEPSS 0.7%CVE-2023-25739HIGHModule load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoaEPSS 0.7%CVE-2023-6866HIGHTypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always EPSS 0.7%CVE-2023-25729HIGHPermission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to opeEPSS 0.7%CVE-2022-26386MEDIUMPreviously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior wEPSS 0.7%CVE-2022-22739MEDIUMMalicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affectEPSS 0.7%CVE-2024-1547MEDIUMThrough a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victEPSS 0.7%CVE-2020-12414—IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly EPSS 0.7%CVE-2020-15662—A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an EPSS 0.7%CVE-2023-25744—Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume thaEPSS 0.7%