Mozilla

Firefox

2867 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.74%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attacker...

  • EPSS 0.53%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers ...

  • EPSS 1.18%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers...

  • EPSS 4.11%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a ...

  • EPSS 4.87%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might al...

  • EPSS 4.44%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow ...

  • EPSS 1.54%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote...

  • EPSS 1.31%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML...

  • EPSS 3.94%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly ex...

  • EPSS 6.1%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute ar...