CVE-2009-4129
- EPSS 0.37%
- Veröffentlicht 14.12.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Race condition in Mozilla Firefox allows remote attackers to produce a JavaScript message with a spoofed domain association by writing the message in between the document request and document load for a web page in a different domain.
CVE-2009-4130
- EPSS 0.51%
- Veröffentlicht 14.12.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the origin domain name of a script via a long name.
CVE-2009-4102
- EPSS 1.46%
- Veröffentlicht 29.11.2009 13:08:29
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.
CVE-2009-3978
- EPSS 0.68%
- Veröffentlicht 19.11.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a la...
- EPSS 8.22%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2009-3378
- EPSS 3.67%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the...
- EPSS 5.15%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overla...
- EPSS 3.64%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code ...
- EPSS 6.19%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
- EPSS 18.23%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or p...