Mozilla

Firefox

2867 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.38%
  • Published 21.10.2007 20:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the tar...

  • EPSS 3.3%
  • Published 21.10.2007 20:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome ...

  • EPSS 20.18%
  • Published 21.10.2007 19:17:00
  • Last modified 09.04.2025 00:30:58

Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.

  • EPSS 14.75%
  • Published 21.10.2007 19:17:00
  • Last modified 09.04.2025 00:30:58

Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.

  • EPSS 0.48%
  • Published 14.10.2007 19:17:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in the sidebar HTML page in the MouseoverDictionary before 0.6.2 extension for Mozilla Firefox allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.25%
  • Published 12.10.2007 21:17:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to de...

  • EPSS 0.23%
  • Published 12.10.2007 21:17:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses '/' (slash) characters to delimit a ...

  • EPSS 1.8%
  • Published 24.09.2007 00:17:00
  • Last modified 09.04.2025 00:30:58

Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows remote attackers to execute arbitrary commands via a QuickTime Media Link (QTL) file with an embed XM...

  • EPSS 1.43%
  • Published 13.09.2007 18:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web site...

  • EPSS 8.93%
  • Published 12.09.2007 20:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper file ty...