CVE-2008-4582
- EPSS 35.58%
- Published 15.10.2008 20:08:02
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the...
- EPSS 6.93%
- Published 29.09.2008 20:09:59
- Last modified 09.04.2025 00:30:58
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and...
- EPSS 29.45%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.
CVE-2008-3835
- EPSS 0.14%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vect...
CVE-2008-3836
- EPSS 3.7%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _in...
CVE-2008-3837
- EPSS 2.56%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted...
CVE-2008-4058
- EPSS 2.43%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vec...
CVE-2008-4059
- EPSS 2.16%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.
CVE-2008-4060
- EPSS 2%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vector...
- EPSS 2.72%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) ...