Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2026-6768CRITICALMitigation bypass in the Networking: Cookies componentEPSS 0.5%CVE-2026-6760CRITICALMitigation bypass in the Networking: Cookies componentEPSS 0.5%CVE-2021-43544—When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caEPSS 0.5%CVE-2024-7518MEDIUMSelect options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vEPSS 0.5%CVE-2025-8028CRITICALLarge branch table could lead to truncated instructionEPSS 0.5%CVE-2025-11708CRITICALUse-after-free in MediaTrackGraphImpl::GetInstance()EPSS 0.5%CVE-2023-28160MEDIUMWhen following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking poEPSS 0.5%CVE-2022-46885HIGHMozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of theEPSS 0.5%CVE-2024-9400HIGHA potential memory corruption vulnerability could be triggered if an attacker had the ability to trigger an OOM at a specific moment during EPSS 0.5%CVE-2025-14330CRITICALJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.5%CVE-2018-5123—A third party website can access information available to a user with access to a restricted bug entry using the image generation in report.EPSS 0.5%CVE-2026-6758HIGHUse-after-free in the JavaScript: WebAssembly componentEPSS 0.5%CVE-2024-2613HIGHData was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulEPSS 0.5%CVE-2026-74956CRITICALSame-origin policy bypass in the DOM: Service Workers componentEPSS 0.5%CVE-2022-36318MEDIUMWhen visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESREPSS 0.5%CVE-2026-92041CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.5%CVE-2026-92057CRITICALMitigation bypass in the Enterprise Policies componentEPSS 0.5%CVE-2024-6612MEDIUMCSP violation leakage when using devtoolsEPSS 0.5%CVE-2026-92075CRITICALMitigation bypass in the Networking componentEPSS 0.5%CVE-2026-0886MEDIUMIncorrect boundary conditions in the Graphics componentEPSS 0.5%