Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2023-32208—Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113.EPSS 0.5%CVE-2024-4771HIGHA memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or poEPSS 0.5%CVE-2023-25740HIGHAfter downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unEPSS 0.5%CVE-2023-29543HIGHAn attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vectEPSS 0.5%CVE-2026-16412CRITICALMemory safety bugs fixed in Firefox ESR 140.13 and Firefox 153EPSS 0.5%CVE-2022-0511HIGHMozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla FuzzEPSS 0.5%CVE-2024-9394MEDIUMAn attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This coEPSS 0.5%CVE-2023-29551HIGHMemory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.5%CVE-2022-22752HIGHMozilla developers Christian Holler and Jason Kratzer reported memory safety bugs present in Firefox 95. Some of these bugs showed evidence EPSS 0.5%CVE-2022-28288HIGHMozilla developers and community members Randell Jesup, Sebastian Hengst, and the Mozilla Fuzzing Team reported memory safety bugs present iEPSS 0.5%CVE-2023-23606HIGHMemory safety bugs fixed in Firefox 109EPSS 0.5%CVE-2026-6759HIGHUse-after-free in the Widget: Cocoa componentEPSS 0.5%CVE-2026-16353CRITICALInvalid pointer in the DOM: Bindings (WebIDL) componentEPSS 0.5%CVE-2026-4726HIGHDenial-of-service in the XML componentEPSS 0.5%CVE-2026-4727HIGHDenial-of-service in the Libraries component in NSSEPSS 0.5%CVE-2026-6781HIGHDenial-of-service in the Audio/Video: Playback componentEPSS 0.5%CVE-2026-6780HIGHDenial-of-service in the Audio/Video: Playback componentEPSS 0.5%CVE-2024-7528CRITICALIncorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox EPSS 0.5%CVE-2023-37204—A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational functEPSS 0.5%CVE-2023-37205—The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefox < 115.EPSS 0.5%