- EPSS 1.37%
- Published 20.05.2010 17:30:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption and application crash) via JavaScript code that creates multiple arrays containing elements with long string values, and then appends lon...
- EPSS 1.37%
- Published 20.05.2010 17:30:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (memory consumption, out-of-bounds read, and application crash) via JavaScript code that appends long strings to the content of a P element, and performs cer...
- EPSS 9.24%
- Published 20.05.2010 17:30:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox 3.6.3 on Windows XP SP3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via JavaScript code that performs certain string concatenation and substr...
- EPSS 0.54%
- Published 20.05.2010 17:30:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox 3.6.x, 3.5.x, 3.0.19, and earlier, and SeaMonkey, executes a mail application in situations where an IFRAME element has a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (excessive applicat...
CVE-2010-1585
- EPSS 0.88%
- Published 28.04.2010 22:30:00
- Last modified 11.04.2025 00:51:21
The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a c...
CVE-2010-0173
- EPSS 7.57%
- Published 05.04.2010 17:30:00
- Last modified 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and applica...
- EPSS 4.23%
- Published 05.04.2010 17:30:00
- Last modified 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory ...
CVE-2010-0175
- EPSS 6.87%
- Published 05.04.2010 17:30:00
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allows remote attackers to execute arbitrary code or cause a denial of se...
CVE-2010-0176
- EPSS 9.82%
- Published 05.04.2010 17:30:00
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to ...
CVE-2010-0177
- EPSS 6.51%
- Published 05.04.2010 17:30:00
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plugins array while a reference to an array element is still active, which allows remote attackers to ex...