CVE-2009-3372
- EPSS 1.99%
- Published 29.10.2009 14:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.
- EPSS 13.49%
- Published 29.10.2009 14:30:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2009-3374
- EPSS 0.89%
- Published 29.10.2009 14:30:00
- Last modified 09.04.2025 00:30:58
The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote w...
CVE-2009-3375
- EPSS 0.46%
- Published 29.10.2009 14:30:00
- Last modified 09.04.2025 00:30:58
content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection fu...
CVE-2009-3376
- EPSS 2.53%
- Published 29.10.2009 14:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via...
CVE-2009-3274
- EPSS 0.1%
- Published 21.09.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary dow...
- EPSS 2.18%
- Published 18.09.2009 22:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop, aka a "printing DoS attack," possibly a related issue to CVE-2009-0821.
- EPSS 5.84%
- Published 10.09.2009 21:30:01
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- EPSS 4.27%
- Published 10.09.2009 21:30:01
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- EPSS 3.35%
- Published 10.09.2009 21:30:01
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via ...