Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2021-23959—An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This iEPSS 0.6%CVE-2026-92051CRITICALSpoofing issue due to invalid pointer in the Graphics componentEPSS 0.6%CVE-2026-2775CRITICALMitigation bypass in the DOM: HTML Parser componentEPSS 0.6%CVE-2024-9398MEDIUMBy checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application whiEPSS 0.6%CVE-2024-10461MEDIUMIn multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a downlEPSS 0.6%CVE-2025-14324CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.6%CVE-2026-16389CRITICALIncorrect boundary conditions, integer overflow in the Libraries component in NSSEPSS 0.6%CVE-2026-4706HIGHIncorrect boundary conditions in the Graphics: Canvas2D componentEPSS 0.6%CVE-2026-4707HIGHIncorrect boundary conditions in the Graphics: Canvas2D componentEPSS 0.6%CVE-2022-22763HIGHWhen a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. TEPSS 0.6%CVE-2024-6607HIGHLeaving pointerlock by pressing the escape key could be preventedEPSS 0.6%CVE-2023-6206—The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possibleEPSS 0.6%CVE-2011-2669—Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.EPSS 0.6%CVE-2022-28286MEDIUMDue to a layout change, iframe contents could have been rendered outside of its border. This could have led to user confusion or spoofing atEPSS 0.6%CVE-2026-84142CRITICALInternally found bugs fixed in Thunderbird 155EPSS 0.6%CVE-2022-29911MEDIUMAn improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execuEPSS 0.6%CVE-2022-0843HIGHMozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugsEPSS 0.6%CVE-2019-9803—The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-EPSS 0.6%CVE-2023-6869MEDIUMA `&lt;dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to diEPSS 0.6%CVE-2026-2781HIGHInteger overflow in the Libraries component in NSSEPSS 0.6%