Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2025-2817HIGHPrivilege escalation in Thunderbird UpdaterEPSS 0.6%CVE-2026-2779CRITICALIncorrect boundary conditions in the Networking: JAR componentEPSS 0.6%CVE-2022-40961MEDIUMDuring startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>EPSS 0.6%CVE-2024-3852HIGHGetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, FireEPSS 0.6%CVE-2022-45407HIGHIf an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentEPSS 0.6%CVE-2019-11754—When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious websiEPSS 0.6%CVE-2023-28161HIGHIf temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permisEPSS 0.6%CVE-2026-2447HIGHHeap buffer overflow in libvpxEPSS 0.6%CVE-2023-4578—Error reporting methods in SpiderMonkey could have triggered an Out of Memory ExceptionEPSS 0.6%CVE-2023-25733HIGHThe return value from `gfx::SourceSurfaceSkia::Map()` wasn't being verified which could have potentially lead to a null pointer dereference.EPSS 0.6%CVE-2026-2773CRITICALIncorrect boundary conditions in the Web Audio componentEPSS 0.6%CVE-2022-29914MEDIUMWhen reusing existing popups Firefox would have allowed them to cover the fullscreen notification UI, which could have enabled browser spoofEPSS 0.6%CVE-2018-5109—An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow tEPSS 0.6%CVE-2024-7521CRITICALIncomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14,EPSS 0.6%CVE-2024-5692MEDIUMOn Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extEPSS 0.6%CVE-2024-9402CRITICALMemory safety bugs present in Firefox 130, Firefox ESR 128.2, and Thunderbird 128.2. Some of these bugs showed evidence of memory corruptionEPSS 0.6%CVE-2023-6210—When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as ifrEPSS 0.6%CVE-2024-3856HIGHA use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects FirEPSS 0.6%CVE-2026-0879CRITICALSandbox escape due to incorrect boundary conditions in the Graphics componentEPSS 0.6%CVE-2025-0237MEDIUMWebChannel APIs susceptible to confused deputy attackEPSS 0.6%