Mozilla

Firefox

3102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.85%
  • Veröffentlicht 21.10.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allow remote attackers to cause a denial of service...

Exploit
  • EPSS 8.7%
  • Veröffentlicht 15.09.2010 20:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attac...

Exploit
  • EPSS 0.64%
  • Veröffentlicht 15.09.2010 20:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a context pointer in conjunction with its successor pointer for seeding of a random number generator, which ...

  • EPSS 0.24%
  • Veröffentlicht 15.09.2010 20:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for seeding of a random number generator, which makes it easier for remote at...

  • EPSS 4.47%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Use-after-free vulnerability in the nsTreeSelection function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code v...

  • EPSS 1.74%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x before 3.1.3 does not properly restrict objects at the end of scope chains, which allows remote attacker...

  • EPSS 0.53%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers ...

  • EPSS 0.88%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict read access to the statusText property of XMLHttpRequest objects, which allows remote attackers...

  • EPSS 4.02%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a ...

  • EPSS 5.22%
  • Veröffentlicht 09.09.2010 19:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might al...