Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2026-8954HIGHIncorrect boundary conditions, integer overflow in the Audio/Video componentEPSS 0.4%CVE-2026-14241HIGHMemory safety bugs fixed in Firefox 152.0.4EPSS 0.4%CVE-2026-6778MEDIUMInvalid pointer in the Audio/Video: Playback componentEPSS 0.4%CVE-2026-4724CRITICALUndefined behavior in the Audio/Video componentEPSS 0.4%CVE-2022-29913MEDIUMThe parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child procesEPSS 0.4%CVE-2024-0754MEDIUMSome WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.EPSS 0.4%CVE-2024-8900HIGHAn attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnEPSS 0.4%CVE-2026-6782HIGHInformation disclosure in the IP Protection componentEPSS 0.4%CVE-2026-84144HIGHInternally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2EPSS 0.4%CVE-2025-1943HIGHMemory safety bugs fixed in Firefox 136 and Thunderbird 136EPSS 0.4%CVE-2026-8967HIGHInformation disclosure in the Graphics: WebGPU componentEPSS 0.4%CVE-2026-8966HIGHInformation disclosure in the IP Protection componentEPSS 0.4%CVE-2026-8965HIGHInformation disclosure in the DOM: Security componentEPSS 0.4%CVE-2025-8036HIGHDNS rebinding circumvents CORSEPSS 0.4%CVE-2026-74976MEDIUMJIT miscompilation in the JavaScript Engine: JIT componentEPSS 0.4%CVE-2022-38475MEDIUMAn attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the valueEPSS 0.4%CVE-2018-5105—WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file runnEPSS 0.4%CVE-2026-92077MEDIUMDenial-of-service in the SVG componentEPSS 0.4%CVE-2026-92078MEDIUMDenial-of-service in the Security componentEPSS 0.4%CVE-2021-23993—An attacker may perform a DoS attack to prevent a user from sending encrypted email to a correspondent. If an attacker creates a crafted OpeEPSS 0.4%