CVE-2010-3167
- EPSS 5.04%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to e...
CVE-2010-3168
- EPSS 5.04%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to c...
CVE-2010-3169
- EPSS 2.91%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memor...
CVE-2010-3131
- EPSS 11.24%
- Veröffentlicht 26.08.2010 18:36:35
- Zuletzt bearbeitet 11.04.2025 00:51:21
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbit...
CVE-2010-2751
- EPSS 0.25%
- Veröffentlicht 30.07.2010 20:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vecto...
CVE-2010-2752
- EPSS 8.93%
- Veröffentlicht 30.07.2010 20:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Casc...
CVE-2010-2753
- EPSS 4.09%
- Veröffentlicht 30.07.2010 20:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a X...
CVE-2010-1207
- EPSS 0.26%
- Veröffentlicht 30.07.2010 20:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node d...
CVE-2010-1208
- EPSS 1.55%
- Veröffentlicht 30.07.2010 20:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors rel...
CVE-2010-1209
- EPSS 2.98%
- Veröffentlicht 30.07.2010 20:30:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM no...