- EPSS 1.63%
- Veröffentlicht 07.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding instead of UTF-8 enc...
CVE-2008-2808
- EPSS 2.08%
- Veröffentlicht 07.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted ...
CVE-2008-2810
- EPSS 0.93%
- Veröffentlicht 07.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has pre...
- EPSS 26.86%
- Veröffentlicht 07.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose di...
CVE-2008-2785
- EPSS 9.52%
- Veröffentlicht 19.06.2008 21:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which all...
- EPSS 0.46%
- Veröffentlicht 19.06.2008 21:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Buffer overflow in Firefox 3.0 and 2.0.x has unknown impact and attack vectors. NOTE: due to lack of details as of 20080619, it is not clear whether this is the same issue as CVE-2008-2785. A CVE identifier has been assigned for tracking purposes.
CVE-2008-2419
- EPSS 5.37%
- Veröffentlicht 23.05.2008 15:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a J...
- EPSS 1.19%
- Veröffentlicht 30.04.2008 01:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.
CVE-2007-6715
- EPSS 0.64%
- Veröffentlicht 17.04.2008 22:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox allows remote attackers to cause a denial of service (crash) via crafted image, as demonstrated by the zzuf lol-firefox.gif test case.
CVE-2008-1380
- EPSS 19.14%
- Veröffentlicht 17.04.2008 19:05:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. ...