Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2024-8394MEDIUMWhen aborting the verification of an OTR chat session, an attacker could have caused a use-after-free bug leading to a potentially exploitabEPSS 0.3%CVE-2025-8029HIGHjavascript: URLs executed on object and embed tagsEPSS 0.3%CVE-2025-8030HIGHPotential user-assisted code execution in “Copy as cURL” commandEPSS 0.3%CVE-2024-11708MEDIUMMissing thread synchronization primitives could have led to a data race on members of the PlaybackParams structure. This vulnerability affecEPSS 0.3%CVE-2024-31393MEDIUMDragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerabilitEPSS 0.3%CVE-2025-8032HIGHXSLT documents could bypass CSPEPSS 0.3%CVE-2021-43531—When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web ExEPSS 0.3%CVE-2025-11715HIGHMemory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144EPSS 0.3%CVE-2025-10537HIGHMemory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143EPSS 0.3%CVE-2025-4090MEDIUMLeaked library paths in Thunderbird for AndroidEPSS 0.3%CVE-2017-7768—The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincEPSS 0.3%CVE-2026-92031MEDIUMInformation disclosure in the Graphics: ImageLib componentEPSS 0.3%CVE-2025-5266MEDIUMScript element events leaked cross-origin resource statusEPSS 0.3%CVE-2023-29549MEDIUMUnder certain circumstances, a call to the <code>bind</code> function may have resulted in the incorrect realm. This may have created a vulnEPSS 0.3%CVE-2026-92042HIGHRace condition in the DOM: Content Processes componentEPSS 0.3%CVE-2016-5295—This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke EPSS 0.3%CVE-2025-5272HIGHMemory safety bugs fixed in Firefox 139 and Thunderbird 139EPSS 0.3%CVE-2024-9395MEDIUMA specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog.
*EPSS 0.3%CVE-2025-1013MEDIUMPotential opening of private browsing tabs in normal browsing windowsEPSS 0.3%CVE-2024-26284MEDIUMUtilizing a 302 redirect, an attacker could have conducted a Universal Cross-Site Scripting (UXSS) on a victim website, if the victim had a EPSS 0.3%