Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2026-74948MEDIUMInformation disclosure in the Graphics componentEPSS 0.4%CVE-2024-4778CRITICALMemory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 0.4%CVE-2026-74945MEDIUMInformation disclosure in the Graphics: Text componentEPSS 0.4%CVE-2024-5700HIGHMemory safety bugs present in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11. Some of these bugs showed evidence of memory corruptiEPSS 0.4%CVE-2026-74954HIGHInformation disclosure due to side-channel in the Storage: Cache API componentEPSS 0.4%CVE-2026-84132HIGHInformation disclosure in the Networking: HTTP componentEPSS 0.4%CVE-2026-4712HIGHInformation disclosure in the Widget: Cocoa componentEPSS 0.4%CVE-2026-8958HIGHInformation disclosure, sandbox escape in the Security: Process Sandboxing componentEPSS 0.4%CVE-2026-84641HIGHInformation disclosure due to malicious IMAP server responseEPSS 0.4%CVE-2026-84130HIGHInformation disclosure in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-74966HIGHInformation disclosure in the Form Autofill componentEPSS 0.4%CVE-2025-3909HIGHJavaScript Execution via Spoofed PDF Attachment and file:/// LinkEPSS 0.4%CVE-2025-1936HIGHAdding %00 and a fake extension to a jar: URL changed the interpretation of the contentsEPSS 0.4%CVE-2026-2782HIGHPrivilege escalation in the Netmonitor componentEPSS 0.4%CVE-2025-0246MEDIUMAddress bar spoofing using an invalid protocol scheme on Firefox for AndroidEPSS 0.4%CVE-2024-2606LOWPassing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulneEPSS 0.4%CVE-2026-84128HIGHPrivilege escalation in the WebDriver BiDi componentEPSS 0.4%CVE-2026-92050CRITICALSandbox escape due to race condition in the XPConnect componentEPSS 0.4%CVE-2024-7531MEDIUMCalling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy BridgeEPSS 0.4%CVE-2026-8972HIGHPrivilege escalation in the WebRTC: Audio/Video componentEPSS 0.4%