Vulnerabilities in Mozilla

1,860 results
Vexday analysis

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2023-5174CRITICALIf Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting inEPSS 1.0%CVE-2022-34484HIGHThe Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruEPSS 1.0%CVE-2024-6602CRITICALMemory corruption in NSSEPSS 1.0%CVE-2020-12398If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue witEPSS 1.0%CVE-2023-5731Memory safety bugs present in Firefox 118. Some of these bugs showed evidence of memory corruption and we presume that with enough effort soEPSS 1.0%CVE-2020-12407Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visEPSS 1.0%CVE-2023-29531CRITICALAn attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crEPSS 1.0%CVE-2021-23965Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presumeEPSS 1.0%CVE-2020-6810After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the broEPSS 1.0%CVE-2024-2612HIGHIf an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveragEPSS 1.0%CVE-2021-29975Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlEPSS 1.0%CVE-2022-29167HIGHReDoS vulnerability in header parsing in hawkEPSS 1.0%CVE-2022-22740HIGHCertain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causiEPSS 1.0%CVE-2023-6860The `VideoBridge` allowed any content process to use textures produced by remote decoders. This could be abused to escape the sandbox. ThisEPSS 1.0%CVE-2023-5732Address bar spoofing via bidirectional charactersEPSS 1.0%CVE-2019-9818A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-EPSS 1.0%CVE-2023-6862A use-after-free was identified in the `nsDNSService::Init`. This issue appears to manifest rarely during start-up. This vulnerability affeEPSS 1.0%CVE-2020-15646If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanEPSS 0.9%CVE-2022-40960MEDIUMConcurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitaEPSS 0.9%CVE-2021-29987After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a differentEPSS 0.9%