Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 14.12.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Race condition in Mozilla Firefox allows remote attackers to produce a JavaScript message with a spoofed domain association by writing the message in between the document request and document load for a web page in a different domain.

  • EPSS 0.51%
  • Veröffentlicht 14.12.2009 17:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the origin domain name of a script via a long name.

  • EPSS 1.46%
  • Veröffentlicht 29.11.2009 13:08:29
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.

  • EPSS 0.68%
  • Veröffentlicht 19.11.2009 00:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a la...

  • EPSS 8.22%
  • Veröffentlicht 29.10.2009 14:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

  • EPSS 3.67%
  • Veröffentlicht 29.10.2009 14:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the...

  • EPSS 5.15%
  • Veröffentlicht 29.10.2009 14:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overla...

  • EPSS 3.64%
  • Veröffentlicht 29.10.2009 14:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code ...

  • EPSS 6.19%
  • Veröffentlicht 29.10.2009 14:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

  • EPSS 18.23%
  • Veröffentlicht 29.10.2009 14:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or p...