Vulnerabilidades em mozilla

2.105 resultados
Análise Vexday

A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.

CVE-2017-5440A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating contexEPSS 2.8%CVE-2017-5408Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading tEPSS 2.8%CVE-2017-5405Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affeEPSS 2.8%CVE-2017-5444A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted dEPSS 2.8%CVE-2021-29978Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd party security audit. EPSS 2.8%CVE-2019-11729Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memEPSS 2.8%CVE-2017-7758An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in useEPSS 2.8%CVE-2017-7753An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerabilityEPSS 2.8%CVE-2018-12366An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This couEPSS 2.8%CVE-2017-5401A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be eEPSS 2.8%CVE-2018-12365A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consentEPSS 2.8%CVE-2018-5099A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been EPSS 2.8%CVE-2018-5103A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially EPSS 2.8%CVE-2018-5148A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a refereEPSS 2.8%CVE-2017-5460A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This resEPSS 2.8%CVE-2018-5096A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. ThisEPSS 2.7%CVE-2018-5187Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that witEPSS 2.7%CVE-2020-15663If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location wiEPSS 2.7%CVE-2020-12388The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only afEPSS 2.7%CVE-2017-5397The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allEPSS 2.7%