Mozilla

Firefox

3102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.05%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objec...

  • EPSS 1.02%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle (1) about:neterror and (2) about:certerror pages, which allows remo...

  • EPSS 3.47%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle certain redirections involving data: URLs and Java LiveConnect scripts, which allows remote attackers to start processes, read arbitrary loca...

  • EPSS 3.85%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 allow remote attackers to cause a denial of service (me...

  • EPSS 6.91%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Unspecified vulnerability in Mozilla Firefox 3.6.x before 3.6.13 and Thunderbird 3.1.x before 3.1.7 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

  • EPSS 5.1%
  • Veröffentlicht 10.12.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Unspecified vulnerability in Mozilla Firefox 3.5.x before 3.5.16, Thunderbird before 3.0.11, and SeaMonkey before 2.0.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code...

  • EPSS 0.48%
  • Veröffentlicht 09.12.2010 20:00:17
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform proxy upgrade negotiation, which has unspecified impact and remote attack vectors, related to an "inherent problem" with the WebSocket specification.

Exploit
  • EPSS 0.17%
  • Veröffentlicht 12.11.2010 22:00:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Mozilla Firefox before 3.6 Beta 3 does not properly handle overlong UTF-8 encoding, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted string, a different vulnerability than CVE-2010-12...

Warnung Medienbericht Exploit
  • EPSS 86.77%
  • Veröffentlicht 28.10.2010 00:00:05
  • Zuletzt bearbeitet 22.04.2026 14:15:57

Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related ...

  • EPSS 0.72%
  • Veröffentlicht 21.10.2010 19:00:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple cross-site scripting (XSS) vulnerabilities in the Gopher parser in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, and SeaMonkey before 2.0.9, allow remote attackers to inject arbitrary web script or HTML via a crafted name of a (1) f...