Mozilla

Firefox

2867 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.13%
  • Published 20.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs...

  • EPSS 8.53%
  • Published 04.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbit...

  • EPSS 6.78%
  • Published 04.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code ...

  • EPSS 0.58%
  • Published 04.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors ...

  • EPSS 1.8%
  • Published 04.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via ...

  • EPSS 0.91%
  • Published 04.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome ...

  • EPSS 0.8%
  • Published 04.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XM...

  • EPSS 0.19%
  • Published 04.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser...

  • EPSS 1.48%
  • Published 22.01.2009 18:30:03
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.

  • EPSS 0.47%
  • Published 20.01.2009 16:30:00
  • Last modified 09.04.2025 00:30:58

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier fo...