Mozilla

Firefox

2867 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.97%
  • Published 26.02.2007 17:28:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site t...

  • EPSS 1.05%
  • Published 23.02.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of...

  • EPSS 0.86%
  • Published 20.02.2007 02:28:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.

Exploit
  • EPSS 18.02%
  • Published 16.02.2007 01:28:00
  • Last modified 09.04.2025 00:30:58

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the h...

  • EPSS 9.33%
  • Published 13.02.2007 11:28:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability ...

Exploit
  • EPSS 0.25%
  • Published 07.02.2007 11:28:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP address in (1) dotted-hex, (2) dotted-octal, (3) single decimal integer, (4) single hex integer, or ...

Exploit
  • EPSS 3.83%
  • Published 07.02.2007 11:28:00
  • Last modified 09.04.2025 00:30:58

Cross-zone vulnerability in Mozilla Firefox 1.5.0.9 considers blocked popups to have an internal zone origin, which allows user-assisted remote attackers to cross zone restrictions and read arbitrary file:// URIs by convincing a user to show a blocke...

Exploit
  • EPSS 0.62%
  • Published 07.02.2007 11:28:00
  • Last modified 09.04.2025 00:30:58

The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.

Exploit
  • EPSS 0.97%
  • Published 07.02.2007 11:28:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist ...

  • EPSS 11.21%
  • Published 20.12.2006 01:28:00
  • Last modified 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and ...