Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2024-10460MEDIUMThe origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects EPSS 0.3%CVE-2025-8040HIGHMemory safety bugs fixed in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141EPSS 0.3%CVE-2026-84639CRITICALUninitialized memory in MIME parsingEPSS 0.3%CVE-2020-12401—During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resultinEPSS 0.3%CVE-2026-16374HIGHInformation disclosure in the Framework component in DevToolsEPSS 0.3%CVE-2026-16391HIGHInformation disclosure in the Storage: IndexedDB componentEPSS 0.3%CVE-2026-6763MEDIUMMitigation bypass in the File Handling componentEPSS 0.3%CVE-2026-84119CRITICALSandbox escape due to use-after-free in the DOM: Navigation componentEPSS 0.3%CVE-2026-84121CRITICALSandbox escape due to use-after-free in the DOM: Security componentEPSS 0.3%CVE-2022-36316MEDIUMWhen using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the targEPSS 0.3%CVE-2025-4087MEDIUMUnsafe attribute access during XPath parsingEPSS 0.3%CVE-2026-16390CRITICALMitigation bypass in the Enterprise Policies componentEPSS 0.3%CVE-2026-92039MEDIUMMitigation bypass in the DOM: Notifications componentEPSS 0.3%CVE-2021-29949—When loading the shared library that provides the OTR protocol implementation, Thunderbird will initially attempt to open it using a filenamEPSS 0.3%CVE-2025-3608MEDIUMRace condition in nsHttpTransaction could lead to memory corruptionEPSS 0.3%CVE-2025-12380CRITICALUse-after-free in WebGPU internals triggered from a compromised child processEPSS 0.3%CVE-2025-14860CRITICALUse-after-free in the Disability Access APIs componentEPSS 0.3%CVE-2026-16361CRITICALMemory safety bugs fixed in Thunderbird ESR 140.13EPSS 0.3%CVE-2023-29540—Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes witEPSS 0.3%CVE-2025-3523MEDIUMUser Interface (UI) Misrepresentation of attachment URLEPSS 0.3%