Vulnerabilidades em mozilla
2.105 resultadosAnálise Vexday
A Mozilla apresenta um perfil de risco baixo com apenas 3 vulnerabilidades catalogadas, nenhuma sob exploração ativa ou crítica. A fraqueza dominante identificada é CWE-400 (Uncontrolled Resource Consumption), que tipicamente afeta disponibilidade; a ausência de publicações recentes sugere que o risco atual não é imediato.
CVE-2025-10527HIGHSandbox escape due to use-after-free in the Graphics: Canvas2D componentEPSS 0.3%CVE-2026-92015HIGHPrivilege escalation in the WebExtensions componentEPSS 0.3%CVE-2026-92012HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2025-13025HIGHIncorrect boundary conditions in the Graphics: WebGPU componentEPSS 0.3%CVE-2026-92011HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92013HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92007HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92010HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92020HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: WebRender componentEPSS 0.3%CVE-2026-92008HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-92009HIGHPrivilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL componentEPSS 0.3%CVE-2026-74951MEDIUMClickjacking issue in Firefox for AndroidEPSS 0.3%CVE-2026-8951MEDIUMSpoofing issue in the Toolbar component in Firefox for AndroidEPSS 0.3%CVE-2026-74980MEDIUMClickjacking issue in the Downloads component in Firefox for AndroidEPSS 0.3%CVE-2024-7523MEDIUMA select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. EPSS 0.3%CVE-2020-12394—A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different oEPSS 0.3%CVE-2025-11712MEDIUMAn OBJECT tag type attribute overrode browser behavior on web resources without a content-typeEPSS 0.3%CVE-2025-10531MEDIUMMitigation bypass in the Web Compatibility: Tooling componentEPSS 0.3%CVE-2023-0163HIGHPrototype Pollution in convictEPSS 0.3%CVE-2024-4765HIGHWeb application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's maEPSS 0.3%