Mozilla

Firefox

2867 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 41.2%
  • Published 02.02.2006 20:06:00
  • Last modified 03.04.2025 01:03:51

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf fil...

Exploit
  • EPSS 11.45%
  • Published 01.02.2006 02:02:00
  • Last modified 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (C...

  • EPSS 0.34%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of ...

Exploit
  • EPSS 12.66%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large value of the WIDTH attribute, which triggers a problem related to representation of floating-point numbe...

Exploit
  • EPSS 10.38%
  • Published 31.12.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.

  • EPSS 29.39%
  • Published 09.12.2005 15:03:00
  • Last modified 03.04.2025 01:03:51

Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not...

  • EPSS 0.72%
  • Published 28.09.2005 18:03:00
  • Last modified 03.04.2025 01:03:51

Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnera...

  • EPSS 8.68%
  • Published 23.09.2005 19:03:00
  • Last modified 03.04.2025 01:03:51

Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.

  • EPSS 6.96%
  • Published 23.09.2005 19:03:00
  • Last modified 03.04.2025 01:03:51

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.

  • EPSS 4.68%
  • Published 23.09.2005 19:03:00
  • Last modified 03.04.2025 01:03:51

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smugglin...