CVE-2008-0419
- EPSS 18.69%
- Published 08.02.2008 22:00:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) via images in a page that uses designMode frames, which triggers memory corruption related to resize ...
- EPSS 0.65%
- Published 19.01.2008 00:00:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing...
CVE-2007-6589
- EPSS 0.55%
- Published 28.12.2007 21:46:00
- Last modified 09.04.2025 00:30:58
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (X...
CVE-2007-5959
- EPSS 11.91%
- Published 26.11.2007 23:46:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption.
CVE-2007-5960
- EPSS 0.69%
- Published 26.11.2007 23:46:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer...
CVE-2007-5947
- EPSS 7.92%
- Published 14.11.2007 01:46:00
- Last modified 09.04.2025 00:30:58
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remot...
CVE-2007-5896
- EPSS 0.62%
- Published 08.11.2007 20:46:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3) fi...
CVE-2007-5691
- EPSS 0.63%
- Published 29.10.2007 19:46:00
- Last modified 09.04.2025 00:30:58
ParseFTPList.cpp in Mozilla Firefox 2.0.0.7 allows remote FTP servers to cause a denial of service (application crash) via a crafted reply to an unspecified listing command, related to "reading from invalid pointer."
CVE-2007-5335
- EPSS 0.71%
- Published 24.10.2007 00:46:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.0 before 2.0.0.8 allows remote attackers to obtain sensitive system information by using the addMicrosummaryGenerator sidebar method to access file: URIs.
CVE-2007-5334
- EPSS 11.56%
- Published 21.10.2007 20:17:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attr...