Mozilla

Firefox

3102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 02.03.2011 20:00:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Cross-site request forgery (CSRF) vulnerability in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, and SeaMonkey before 2.0.12, allows remote attackers to hijack the authentication of arbitrary users for requests that were initiated by a plugi...

  • EPSS 4.13%
  • Veröffentlicht 02.03.2011 20:00:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Buffer overflow in Mozilla Firefox 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG image.

  • EPSS 7.14%
  • Veröffentlicht 02.03.2011 20:00:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arb...

  • EPSS 7.15%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Use-after-free vulnerability in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via vectors involving a change to an nsDOMAttribute node.

  • EPSS 4.62%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements.

  • EPSS 6.14%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows...

  • EPSS 8.4%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers t...

  • EPSS 8.05%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2)...

  • EPSS 2.24%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome priv...

  • EPSS 5.43%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV ...