Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2025-49709CRITICALMemory corruption in canvas surfacesEPSS 0.7%CVE-2022-31741HIGHA crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. TEPSS 0.7%CVE-2024-6611CRITICALIncorrect handling of SameSite cookiesEPSS 0.7%CVE-2024-0745HIGHThe WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. ThiEPSS 0.7%CVE-2022-36320CRITICALMozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of meEPSS 0.7%CVE-2026-92240CRITICALOut-of-bounds read in IMAP response parserEPSS 0.7%CVE-2026-2796CRITICALJIT miscompilation in the JavaScript: WebAssembly componentEPSS 0.7%CVE-2023-4051—Full screen notification obscured by file open dialogEPSS 0.7%CVE-2023-4575—Memory corruption in IPC FilePickerShownCallbackEPSS 0.7%CVE-2022-26387HIGHWhen installing an add-on, Firefox verified the signature before prompting the user; but while the user was confirming the prompt, the underEPSS 0.7%CVE-2021-23955—The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks.EPSS 0.7%CVE-2021-23963—When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to EPSS 0.7%CVE-2024-7652HIGHType Confusion in Async Generators in Javascript EngineEPSS 0.7%CVE-2022-31748CRITICALMozilla developers Gabriele Svelto, Timothy Nikkel, Randell Jesup, Jon Coppeard, and the Mozilla Fuzzing Team reported memory safety bugs prEPSS 0.7%CVE-2024-11705CRITICAL`NSC_DeriveKey` inadvertently assumed that the `phKey` parameter is always non-NULL. When it was passed as NULL, a segmentation fault (SEGV)EPSS 0.7%CVE-2022-26383MEDIUMWhen resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affectEPSS 0.7%CVE-2024-5691MEDIUMBy tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would EPSS 0.7%CVE-2022-46880MEDIUMA missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was adEPSS 0.7%CVE-2023-4577—Memory corruption in JIT UpdateRegExpStaticsEPSS 0.7%CVE-2022-22741HIGHWhen resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability afEPSS 0.7%