CVE-2009-2472
- EPSS 0.7%
- Veröffentlicht 22.07.2009 18:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, re...
- EPSS 10.79%
- Veröffentlicht 20.07.2009 18:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a re...
- EPSS 4.07%
- Veröffentlicht 16.07.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, related to a "flash bug."
CVE-2009-2479
- EPSS 13.47%
- Veröffentlicht 16.07.2009 15:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-bas...
CVE-2009-2477
- EPSS 83.03%
- Veröffentlicht 15.07.2009 15:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized mem...
CVE-2009-0689
- EPSS 41.05%
- Veröffentlicht 01.07.2009 13:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD...
CVE-2009-2061
- EPSS 0.35%
- Veröffentlicht 15.06.2009 19:30:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify...
CVE-2009-2065
- EPSS 0.3%
- Veröffentlicht 15.06.2009 19:30:05
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying ...
CVE-2009-1392
- EPSS 15.73%
- Veröffentlicht 12.06.2009 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vect...
CVE-2009-1832
- EPSS 10.37%
- Veröffentlicht 12.06.2009 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double fra...