Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.92%—Mozilla Firefox Mobile9/12/202019/8/2026
If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web content. The feature was implemented as a unix domain socket, protected…
ModificadaMedia (6.5)0.55%—Mozilla Firefox Mobile9/12/202019/8/2026
OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
ModificadaMedia (6.5)0.83%—Mozilla Firefox Mobile9/12/202019/8/2026
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for…
ModificadaMedia (4.3)0.64%—Mozilla Firefox Mobile9/12/202019/8/2026
When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note:…
ModificadaMedia (5.3)1.5%—Mozilla FirefoxMozilla Firefox Mobile28/10/202019/8/2026
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a few signature generations, the private key could have been computed. This vulnerability affects…
ModificadaMedia (4.7)0.32%—Mozilla FirefoxMozilla Firefox Mobile8/10/202019/8/2026
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
ModificadaMedia (4.7)0.27%—Mozilla FirefoxMozilla Firefox Mobile8/10/202019/8/2026
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
ModificadaBaja (3.1)0.49%—Mozilla Firefox Mobile1/10/202019/8/2026
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.
ModificadaAlta (8.8)1.1%—Mozilla FirefoxMozilla Firefox ESRMozilla Firefox MobileMozilla Thunderbird1/10/202019/8/2026
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 80, Firefox ESR < 78.2, Thunderbird <…
ModificadaMedia (4.3)0.53%—Mozilla FirefoxMozilla Firefox Mobile1/10/202019/8/2026
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
ModificadaMedia (6.5)1.2%—Mozilla FirefoxMozilla Firefox Mobile1/10/202019/8/2026
When trying to load a non-video in an audio/video context the exact status code (200, 302, 404, 500, 412, 403, etc.) was disclosed via the MediaError Message. This level of information leakage is inconsistent with the standardized onerror/onsuccess disclosure and can lead to inferring login status to services or…
ModificadaMedia (6.5)1.4%—Mozilla FirefoxMozilla Firefox ESRMozilla Firefox MobileMozilla Thunderbird1/10/202019/8/2026
By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this could result in an unintended or malicious extension being installed.…
ModificadaMedia (6.5)0.67%—Mozilla Firefox Mobile10/8/202019/8/2026
A rogue webpage could override the injected WKUserScript used by the download feature, this exploit could result in the user downloading an unintended file. This vulnerability affects Firefox for iOS < 28.
ModificadaMedia (6.5)0.84%—Mozilla Firefox Mobile10/8/202019/8/2026
A rogue webpage could override the injected WKUserScript used by the logins autofill, this exploit could result in leaking a password for the current domain. This vulnerability affects Firefox for iOS < 28.
ModificadaMedia (6.5)0.67%—Mozilla Firefox Mobile9/7/202019/8/2026
IndexedDB should be cleared when leaving private browsing mode and it is not, the API for WKWebViewConfiguration was being used incorrectly and requires the private instance of this object be deleted when leaving private mode. This vulnerability affects Firefox for iOS < 27.
ModificadaMedia (4.3)0.78%—Mozilla Firefox Mobile9/7/202019/8/2026
For native-to-JS bridging the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token could leak when used for downloading files. This vulnerability affects Firefox for iOS < 26.
ModificadaAlta (7.5)0.90%—Mozilla Firefox Mobile26/5/202019/8/2026
For native-to-JS bridging, the app requires a unique token to be passed that ensures non-app code can't call the bridging functions. That token was being used for JS-to-native also, but it isn't needed in this case, and its usage was also leaking this token. This vulnerability affects Firefox for iOS < 25.
ModificadaMedia (6.8)1.9%—Mozilla FirefoxMozilla Firefox MobileGoogle Android29/8/201216/6/2026
Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the JavaScript dump function.
ModificadaAlta (9.3)4.9%—FreetypeMozilla Firefox Mobile25/4/201216/6/2026
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via a crafted TrueType font.
ModificadaMedia (4.3)1.6%—FreetypeMozilla Firefox Mobile25/4/201216/6/2026
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted font.
ModificadaAlta (9.3)3.8%—FreetypeMozilla Firefox Mobile25/4/201216/6/2026
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap write operation and memory corruption) or possibly execute arbitrary code via crafted glyph-outline data in a font.
ModificadaAlta (9.3)3.8%—FreetypeMozilla Firefox Mobile25/4/201216/6/2026
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted ASCII string in a BDF font.
ModificadaAlta (9.3)3.8%—FreetypeMozilla Firefox Mobile25/4/201216/6/2026
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via a crafted PostScript font object.
ModificadaAlta (9.3)3.8%—FreetypeMozilla Firefox Mobile25/4/201216/6/2026
Array index error in FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid stack read operation and memory corruption) or possibly execute arbitrary code via crafted glyph data in a BDF font.
ModificadaAlta (9.3)4.7%—FreetypeMozilla Firefox Mobile25/4/201216/6/2026
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via vectors involving the MIRP instruction in a TrueType font.
Orbitaley — Vulnerabilidades