CVE-2009-0358
- EPSS 0.19%
- Veröffentlicht 04.02.2009 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser...
CVE-2009-0253
- EPSS 1.48%
- Veröffentlicht 22.01.2009 18:30:03
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.
CVE-2008-5913
- EPSS 0.47%
- Veröffentlicht 20.01.2009 16:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier fo...
CVE-2009-0071
- EPSS 6.52%
- Veröffentlicht 08.01.2009 19:30:11
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a ...
- EPSS 8.29%
- Veröffentlicht 24.12.2008 18:29:15
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash). NOTE: it was later reported that earlier versions ...
- EPSS 3.55%
- Veröffentlicht 17.12.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via ve...
- EPSS 4.54%
- Veröffentlicht 17.12.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.
- EPSS 3.77%
- Veröffentlicht 17.12.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEnti...
CVE-2008-5503
- EPSS 1.14%
- Veröffentlicht 17.12.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or...
CVE-2008-5504
- EPSS 3.7%
- Veröffentlicht 17.12.2008 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.