CVE-2010-3778
- EPSS 5.1%
- Published 10.12.2010 19:00:02
- Last modified 11.04.2025 00:51:21
Unspecified vulnerability in Mozilla Firefox 3.5.x before 3.5.16, Thunderbird before 3.0.11, and SeaMonkey before 2.0.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code...
- EPSS 0.48%
- Published 09.12.2010 20:00:17
- Last modified 11.04.2025 00:51:21
The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform proxy upgrade negotiation, which has unspecified impact and remote attack vectors, related to an "inherent problem" with the WebSocket specification.
CVE-2009-5017
- EPSS 0.17%
- Published 12.11.2010 22:00:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-12...
CVE-2010-3765
- EPSS 87.21%
- Published 28.10.2010 00:00:05
- Last modified 07.10.2025 01:00:02
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related ...
CVE-2010-3177
- EPSS 0.72%
- Published 21.10.2010 19:00:03
- Last modified 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) f...
CVE-2010-3178
- EPSS 0.86%
- Published 21.10.2010 19:00:03
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly handle certain modal calls made by javascript: URLs in circumstances related to opening a new window an...
CVE-2010-3179
- EPSS 29.29%
- Published 21.10.2010 19:00:03
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or...
CVE-2010-3180
- EPSS 7.2%
- Published 21.10.2010 19:00:03
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the nsBarProp function in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code by accessin...
CVE-2010-3181
- EPSS 0.06%
- Published 21.10.2010 19:00:03
- Last modified 11.04.2025 00:51:21
Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Windows allows local users to gain privileges via a Trojan horse DLL in the c...
CVE-2010-3182
- EPSS 0.11%
- Published 21.10.2010 19:00:03
- Last modified 11.04.2025 00:51:21
A certain application-launch script in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Linux places a zero-length directory name in the LD_LIBRARY_PATH, which allow...