- EPSS 2.48%
- Veröffentlicht 22.02.2010 13:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute ...
- EPSS 5.18%
- Veröffentlicht 22.02.2010 13:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap me...
CVE-2010-0162
- EPSS 0.82%
- Veröffentlicht 22.02.2010 13:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving S...
- EPSS 5.46%
- Veröffentlicht 22.02.2010 13:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that at...
- EPSS 0.17%
- Veröffentlicht 22.02.2010 13:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-s...
CVE-2010-0648
- EPSS 0.44%
- Veröffentlicht 18.02.2010 18:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the do...
CVE-2010-0654
- EPSS 0.7%
- Veröffentlicht 18.02.2010 18:00:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type ...
- EPSS 0.23%
- Veröffentlicht 29.01.2010 18:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML documents, which makes it easier for remote attackers to determine the network location of the applica...
- EPSS 0.95%
- Veröffentlicht 07.01.2010 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an acco...
CVE-2009-3388
- EPSS 2.63%
- Veröffentlicht 17.12.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."