CVE-2009-3981
- EPSS 3.87%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
CVE-2009-3982
- EPSS 8.29%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exe...
CVE-2009-3983
- EPSS 1.03%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary applications by replaying the NTLM credentials of a browser user.
CVE-2009-3984
- EPSS 2.58%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL or a file URL by setting document.location to an https URL corresponding to a site that responds with ...
CVE-2009-3985
- EPSS 0.69%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.location to this URL, and then writing arbitrary web script or HTML to the ...
CVE-2009-3986
- EPSS 2.43%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a reference to a chrome window from a content window, related to the window...
CVE-2009-3987
- EPSS 0.81%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote ...
CVE-2009-4129
- EPSS 0.37%
- Published 14.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Race condition in Mozilla Firefox allows remote attackers to produce a JavaScript message with a spoofed domain association by writing the message in between the document request and document load for a web page in a different domain.
CVE-2009-4130
- EPSS 0.51%
- Published 14.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the origin domain name of a script via a long name.
CVE-2009-4102
- EPSS 1.46%
- Published 29.11.2009 13:08:29
- Last modified 09.04.2025 00:30:58
Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.