CVE-2009-3987
- EPSS 0.81%
- Veröffentlicht 17.12.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether the referenced COM object is listed in the registry, which allows remote ...
CVE-2009-4129
- EPSS 0.37%
- Veröffentlicht 14.12.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Race condition in Mozilla Firefox allows remote attackers to produce a JavaScript message with a spoofed domain association by writing the message in between the document request and document load for a web page in a different domain.
CVE-2009-4130
- EPSS 0.51%
- Veröffentlicht 14.12.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the origin domain name of a script via a long name.
CVE-2009-4102
- EPSS 1.46%
- Veröffentlicht 29.11.2009 13:08:29
- Zuletzt bearbeitet 09.04.2025 00:30:58
Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.
CVE-2009-3978
- EPSS 0.68%
- Veröffentlicht 19.11.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a la...
- EPSS 7%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2009-3378
- EPSS 3.28%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the...
- EPSS 4.87%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overla...
- EPSS 3.64%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code ...
- EPSS 5.85%
- Veröffentlicht 29.10.2009 14:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.