Mozilla

Firefox

2867 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.6%
  • Published 06.06.2007 10:30:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.

  • EPSS 45.04%
  • Published 01.06.2007 00:30:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter w...

  • EPSS 31.32%
  • Published 01.06.2007 00:30:00
  • Last modified 09.04.2025 00:30:58

Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of servic...

  • EPSS 38.44%
  • Published 01.06.2007 00:30:00
  • Last modified 09.04.2025 00:30:58

Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of se...

  • EPSS 15.92%
  • Published 01.06.2007 00:30:00
  • Last modified 09.04.2025 00:30:58

The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in...

  • EPSS 8%
  • Published 01.06.2007 00:30:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add...

  • EPSS 16.41%
  • Published 01.06.2007 00:30:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: th...

Exploit
  • EPSS 6.52%
  • Published 14.05.2007 23:19:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A element, which triggers an out-of-bounds memory access.

  • EPSS 1.54%
  • Published 26.04.2007 20:19:00
  • Last modified 09.04.2025 00:30:58

CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allows remote attackers to conduct HTTP request splitting attacks via LF (%0a) bytes in the username attribute.

  • EPSS 2.68%
  • Published 24.04.2007 16:19:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. NOTE: this might be the same issue as CVE-2007-2175.