CVE-2010-3768
- EPSS 6.82%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows...
CVE-2010-3769
- EPSS 6.36%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers t...
CVE-2010-3770
- EPSS 9.32%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2)...
CVE-2010-3771
- EPSS 2.24%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome priv...
CVE-2010-3772
- EPSS 5.53%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV ...
CVE-2010-3773
- EPSS 1.25%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objec...
CVE-2010-3774
- EPSS 1.17%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle (1) about:neterror and (2) about:certerror pages, which allows remo...
CVE-2010-3775
- EPSS 4.6%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle certain redirections involving data: URLs and Java LiveConnect scripts, which allows remote attackers to start processes, read arbitrary loca...
CVE-2010-3776
- EPSS 3.8%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (me...
CVE-2010-3777
- EPSS 6.91%
- Veröffentlicht 10.12.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.