Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2025-0240MEDIUMCompartment mismatch when parsing JavaScript JSON moduleEPSS 0.7%CVE-2023-25728MEDIUMThe <code>Content-Security-Policy-Report-Only</code> header could allow an attacker to leak a child iframe's unredacted URI when interactionEPSS 0.7%CVE-2022-45416MEDIUMKeyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as PriEPSS 0.7%CVE-2024-1552HIGHIncorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects EPSS 0.7%CVE-2021-29958—When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to private mode cookiesEPSS 0.7%CVE-2024-3859MEDIUMOn 32-bit versions there were integer-overflows that led to an out-of-bounds-read that potentially could be triggered by a malformed OpenTypEPSS 0.7%CVE-2023-3417—File Extension Spoofing using the Text Direction Override CharacterEPSS 0.7%CVE-2021-29979—Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in the Hub Cloud instanEPSS 0.7%CVE-2023-25746HIGHMemory safety bugs present in Firefox ESR 102.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effEPSS 0.7%CVE-2023-25745HIGHMemory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.7%CVE-2023-6213—Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.7%CVE-2017-7759—Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reaEPSS 0.7%CVE-2020-6803MEDIUMOpen redirect in Mozilla WebThings GatewayEPSS 0.7%CVE-2026-4689CRITICALSandbox escape due to incorrect boundary conditions, integer overflow in the XPCOM componentEPSS 0.7%CVE-2023-6857—When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affEPSS 0.7%CVE-2026-0880HIGHSandbox escape due to integer overflow in the Graphics componentEPSS 0.7%CVE-2019-25136CRITICALA compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox EPSS 0.7%CVE-2023-4574—Memory corruption in IPC ColorPickerShownCallbackEPSS 0.7%CVE-2022-3032—When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HEPSS 0.7%CVE-2022-31739HIGHWhen downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-EPSS 0.7%