Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 23.74%
  • Veröffentlicht 22.07.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ...

  • EPSS 4.12%
  • Veröffentlicht 22.07.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or ...

  • EPSS 2.11%
  • Veröffentlicht 22.07.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.

  • EPSS 0.7%
  • Veröffentlicht 22.07.2009 18:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, re...

  • EPSS 10.79%
  • Veröffentlicht 20.07.2009 18:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumption and application crash) via a large integer value for the length property of a Select object, a re...

Exploit
  • EPSS 4.07%
  • Veröffentlicht 16.07.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, related to a "flash bug."

Exploit
  • EPSS 13.47%
  • Veröffentlicht 16.07.2009 15:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-bas...

Exploit
  • EPSS 83.03%
  • Veröffentlicht 15.07.2009 15:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized mem...

Exploit
  • EPSS 41.76%
  • Veröffentlicht 01.07.2009 13:00:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 15.06.2009 19:30:05
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site's context, by modifying this CONNECT response to specify...