Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2026-6748CRITICALUninitialized memory in the Audio/Video: Web Codecs componentEPSS 0.6%CVE-2026-8401CRITICALSandbox escape in the Profile Backup componentEPSS 0.6%CVE-2024-0742MEDIUMIt was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestaEPSS 0.6%CVE-2026-8091CRITICALIncorrect boundary conditions in the Audio/Video: Playback componentEPSS 0.6%CVE-2026-4692CRITICALSandbox escape in the Responsive Design Mode componentEPSS 0.6%CVE-2026-4687CRITICALSandbox escape due to incorrect boundary conditions in the Telemetry componentEPSS 0.6%CVE-2026-4720CRITICALMemory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149EPSS 0.6%CVE-2024-2615CRITICALMemory safety bugs present in Firefox 123. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.6%CVE-2024-8382HIGHInternal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web contEPSS 0.6%CVE-2020-12413MEDIUMThe Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabledEPSS 0.6%CVE-2023-4045—Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violatioEPSS 0.6%CVE-2021-23998—Through complicated navigations with new windows, an HTTP page could have inherited a secure lock icon from an HTTPS page. This vulnerabilitEPSS 0.6%CVE-2023-37209—A use-after-free condition existed in `NotifyOnHistoryReload` where a `LoadingSessionHistoryEntry` object was freed and a reference to that EPSS 0.6%CVE-2022-31742MEDIUMAn attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between iEPSS 0.6%CVE-2026-2769HIGHUse-after-free in the Storage: IndexedDB componentEPSS 0.6%CVE-2026-74936CRITICALUse-after-free in the JavaScript: WebAssembly componentEPSS 0.6%CVE-2025-1016CRITICALMemory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7EPSS 0.6%CVE-2026-74944CRITICALUse-after-free in the DOM: Core & HTML componentEPSS 0.6%CVE-2024-4770HIGHWhen saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126,EPSS 0.6%CVE-2021-38497—Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to poEPSS 0.6%