Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2017-5440—A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating contexEPSS 2.8%CVE-2017-5408—Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading tEPSS 2.8%CVE-2017-5405—Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affeEPSS 2.8%CVE-2017-5444—A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted dEPSS 2.8%CVE-2021-29978—Multiple low security issues were discovered and fixed in a security audit of Mozilla VPN 2.x branch as part of a 3rd party security audit. EPSS 2.8%CVE-2019-11729—Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memEPSS 2.8%CVE-2017-7758—An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in useEPSS 2.8%CVE-2017-7753—An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerabilityEPSS 2.8%CVE-2018-12366—An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This couEPSS 2.8%CVE-2017-5401—A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be eEPSS 2.8%CVE-2018-12365—A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consentEPSS 2.8%CVE-2018-5099—A use-after-free vulnerability can occur when the widget listener is holding strong references to browser objects that have previously been EPSS 2.8%CVE-2018-5103—A use-after-free vulnerability can occur during mouse event handling due to issues with multiprocess support. This results in a potentially EPSS 2.8%CVE-2018-5148—A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a refereEPSS 2.8%CVE-2017-5460—A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This resEPSS 2.8%CVE-2018-5096—A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. ThisEPSS 2.7%CVE-2018-5187—Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that witEPSS 2.7%CVE-2020-15663—If Firefox is installed to a user-writable directory, the Mozilla Maintenance Service would execute updater.exe from the install location wiEPSS 2.7%CVE-2020-12388—The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only afEPSS 2.7%CVE-2017-5397—The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allEPSS 2.7%