Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2017-5390—The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers EPSS 3.9%CVE-2021-38503—The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scriptsEPSS 3.8%CVE-2018-5177—A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a bufferEPSS 3.8%CVE-2018-12362—An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in aEPSS 3.8%CVE-2017-5397—The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allEPSS 3.8%CVE-2018-5156—A vulnerability can occur when capturing a media stream when the media source type is changed as the capture is occurring. This can result iEPSS 3.8%CVE-2017-5398—Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enougEPSS 3.7%CVE-2025-6424CRITICALUse-after-free in FontFaceSetEPSS 3.6%CVE-2016-5297—An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerabiliEPSS 3.6%CVE-2017-7824—A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incEPSS 3.6%CVE-2017-5400—JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruptionEPSS 3.6%CVE-2017-5439—A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitableEPSS 3.6%CVE-2017-5434—A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability aEPSS 3.6%CVE-2017-5438—A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results EPSS 3.6%CVE-2017-5433—A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animaEPSS 3.6%CVE-2019-17006—In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application cEPSS 3.6%CVE-2016-9898—Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox <EPSS 3.5%CVE-2025-6436HIGHMemory safety bugs fixed in Firefox 140 and Thunderbird 140EPSS 3.5%CVE-2017-5455—The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with anoEPSS 3.5%CVE-2016-5296—A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. TEPSS 3.5%