- EPSS 5.18%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in the plugin API in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- EPSS 2.98%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitr...
CVE-2011-2999
- EPSS 0.72%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a diffe...
CVE-2011-3000
- EPSS 1.3%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote a...
CVE-2011-3001
- EPSS 0.2%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions ...
CVE-2011-3002
- EPSS 2.07%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service (application ...
- EPSS 1.51%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unspecified WebGL test case that triggers a memory-allocation error and a resulting ...
CVE-2011-3004
- EPSS 0.31%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
The JSSubScriptLoader in Mozilla Firefox 4.x through 6 and SeaMonkey before 2.4 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a craf...
CVE-2011-3005
- EPSS 3.36%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OGG headers in a ....
CVE-2011-3232
- EPSS 4.66%
- Published 29.09.2011 00:55:01
- Last modified 11.04.2025 00:51:21
YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.