CVE-2008-4582
- EPSS 35.58%
- Veröffentlicht 15.10.2008 20:08:02
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the...
- EPSS 6.93%
- Veröffentlicht 29.09.2008 20:09:59
- Zuletzt bearbeitet 09.04.2025 00:30:58
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and...
- EPSS 29.45%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.
CVE-2008-3835
- EPSS 0.14%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vect...
CVE-2008-3836
- EPSS 3.7%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _in...
CVE-2008-3837
- EPSS 2.56%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted...
CVE-2008-4058
- EPSS 2.43%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vec...
CVE-2008-4059
- EPSS 2.16%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.
CVE-2008-4060
- EPSS 2%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vector...
- EPSS 2.72%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) ...