CVE-2010-1210
- EPSS 0.25%
- Published 30.07.2010 20:30:01
- Last modified 11.04.2025 00:51:21
intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to cond...
CVE-2010-1211
- EPSS 2.85%
- Published 30.07.2010 20:30:01
- Last modified 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow remote attackers to cause a denial of se...
CVE-2010-1212
- EPSS 2.03%
- Published 30.07.2010 20:30:01
- Last modified 11.04.2025 00:51:21
js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via v...
CVE-2010-1213
- EPSS 0.2%
- Published 30.07.2010 20:30:01
- Last modified 11.04.2025 00:51:21
The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows r...
CVE-2010-1214
- EPSS 5.79%
- Published 30.07.2010 20:30:01
- Last modified 11.04.2025 00:51:21
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.
CVE-2010-1215
- EPSS 0.48%
- Published 30.07.2010 20:30:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrom...
- EPSS 0.26%
- Published 30.07.2010 13:26:18
- Last modified 11.04.2025 00:51:21
dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not properly suppress a script's URL in certain circumstances involving...
- EPSS 6.73%
- Published 30.07.2010 13:26:18
- Last modified 11.04.2025 00:51:21
layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via...
CVE-2010-1205
- EPSS 17.03%
- Published 30.06.2010 18:30:01
- Last modified 11.04.2025 00:51:21
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
CVE-2010-1206
- EPSS 0.48%
- Published 25.06.2010 19:30:01
- Last modified 11.04.2025 00:51:21
The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the ab...