- EPSS 2.03%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or po...
CVE-2008-4063
- EPSS 2.87%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1)...
- EPSS 2.27%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to graphics rendering and (1...
CVE-2008-4065
- EPSS 1.31%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) charact...
CVE-2008-4066
- EPSS 1.2%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as...
CVE-2008-4067
- EPSS 1.72%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) ...
CVE-2008-4068
- EPSS 0.19%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive inf...
- EPSS 0.89%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.
CVE-2008-3444
- EPSS 0.77%
- Published 04.08.2008 10:59:00
- Last modified 09.04.2025 00:30:58
The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML ...
CVE-2008-2933
- EPSS 7.09%
- Published 17.07.2008 13:41:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations in...