CVE-2007-2162
- EPSS 0.62%
- Published 22.04.2007 19:19:00
- Last modified 09.04.2025 00:30:58
(1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial of service (browser crash or system hang) via JavaScript that matches a regular expression against a long string, as demonstrated using /(.)*/.
- EPSS 0.27%
- Published 11.04.2007 10:19:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.write, which allows remote attackers to supply unauthenticated content and conduct phishing attacks.
- EPSS 0.2%
- Published 30.03.2007 00:19:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote attackers to bypass phishing protection via multiple / (slash) characters in the URL.
CVE-2007-1736
- EPSS 0.13%
- Published 28.03.2007 22:19:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote attackers to bypass phishing protection.
CVE-2007-1562
- EPSS 29.04%
- Published 21.03.2007 19:19:00
- Last modified 09.04.2025 00:30:58
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate...
- EPSS 18.26%
- Published 10.03.2007 00:19:00
- Last modified 09.04.2025 00:30:58
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspecified resource consumption) via a .pdf URL with an anchor identifier that begins with search= followe...
CVE-2007-0994
- EPSS 2.5%
- Published 06.03.2007 00:19:00
- Last modified 09.04.2025 00:30:58
A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote attackers to execute arbitrary JavaScript as the user via an HTML mail message with a javascript: URI...
CVE-2007-1256
- EPSS 0.54%
- Published 03.03.2007 20:19:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to anoth...
CVE-2007-0996
- EPSS 2.42%
- Published 27.02.2007 02:28:00
- Last modified 09.04.2025 00:30:58
The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated us...
- EPSS 0.55%
- Published 26.02.2007 23:28:00
- Last modified 09.04.2025 00:30:58
The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.