Vulnerabilidades em Mozilla

1.860 resultados
Análise Vexday

Com 1.857 CVEs catalogadas e 189 classificadas como críticas, o histórico de vulnerabilidades da Mozilla reflete a complexidade de manter um navegador amplamente adotado. A taxa de exploração ativa — 9 entradas no CISA KEV, representando 0,48% do total — está em linha com a média geral do catálogo, o que indica um nível de exposição operacional compatível com o setor, sem desvio negativo expressivo. O tipo de falha mais recorrente é CWE-416 (use-after-free), uma classe de vulnerabilidade de memória com alto potencial de execução de código, e a CVE mais perigosa atualmente ativa, CVE-2016-9079, apresenta EPSS de 0,8792 — valor elevado que sugere probabilidade significativa de exploração continuada. Os 144 CVEs surgidos nos últimos 90 dias e a existência de 27 provas de conceito públicas reforçam a necessidade de monitoramento contínuo e priorização ágil de patches para ambientes que dependem de produtos Mozilla.

CVE-2020-15659Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed eEPSS 2.4%CVE-2016-9905A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < EPSS 2.4%CVE-2018-12373dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerabiliEPSS 2.4%CVE-2018-5130When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triEPSS 2.4%CVE-2018-5117If right-to-left text is used in the addressbar with left-to-right alignment, it is possible in some circumstances to scroll this text to spEPSS 2.4%CVE-2018-5168Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. TEPSS 2.4%CVE-2017-7787Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content onEPSS 2.4%CVE-2017-5419If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-responsive, requiring shutdEPSS 2.4%CVE-2019-11709Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed eEPSS 2.3%CVE-2022-26486CRITICALAn unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attaEPSS 2.3%KEVCVE-2018-12389Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memoEPSS 2.3%CVE-2017-7793A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting inEPSS 2.3%CVE-2017-7788When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's EPSS 2.3%CVE-2018-5131Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" EPSS 2.3%CVE-2020-12419When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-freEPSS 2.3%CVE-2018-5180A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability iEPSS 2.3%CVE-2018-12401Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This EPSS 2.3%CVE-2016-5285A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssEPSS 2.3%CVE-2017-7811Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effoEPSS 2.3%CVE-2017-5399Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effoEPSS 2.3%