Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2024-1557HIGHMemory safety bugs present in Firefox 122. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.6%CVE-2023-25731HIGHDue to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwriteEPSS 0.6%CVE-2026-2806CRITICALUninitialized memory in the Graphics: Text componentEPSS 0.6%CVE-2026-8391MEDIUMOther issue in the JavaScript Engine componentEPSS 0.6%CVE-2023-29537—Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnEPSS 0.6%CVE-2026-4715CRITICALUninitialized memory in the Graphics: Canvas2D componentEPSS 0.6%CVE-2026-74986CRITICALSite isolation issue in the CSS Parsing and Computation componentEPSS 0.6%CVE-2026-4716CRITICALIncorrect boundary conditions, uninitialized memory in the JavaScript Engine componentEPSS 0.6%CVE-2026-84639CRITICALUninitialized memory in MIME parsingEPSS 0.6%CVE-2026-4711CRITICALUse-after-free in the Widget: Cocoa componentEPSS 0.6%CVE-2026-4701CRITICALUse-after-free in the JavaScript Engine componentEPSS 0.6%CVE-2022-26385MEDIUMIn unusual circumstances, an individual thread may outlive the thread's manager during shutdown. This could have led to a use-after-free cauEPSS 0.6%CVE-2025-1937HIGHMemory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8EPSS 0.6%CVE-2022-34477HIGHThe MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site crosEPSS 0.6%CVE-2022-28287MEDIUMIn unusual circumstances, selecting text could cause text selection caching to behave incorrectly, leading to a crash. This vulnerability afEPSS 0.5%CVE-2026-4700CRITICALMitigation bypass in the Networking: HTTP componentEPSS 0.5%CVE-2020-26957—OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce EPSS 0.5%CVE-2022-28284HIGHSVG's <code><use></code> element could have been used to load unexpected content that could have executed script in certain circumstanEPSS 0.5%CVE-2021-4128MEDIUMWhen transitioning in and out of fullscreen mode, a graphics object was not correctly protected; resulting in memory corruption and a potentEPSS 0.5%CVE-2023-25730MEDIUMA background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode iEPSS 0.5%