CVE-2008-5024
- EPSS 7.22%
- Veröffentlicht 13.11.2008 11:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection at...
- EPSS 23.01%
- Veröffentlicht 13.11.2008 11:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that ...
CVE-2008-4723
- EPSS 0.21%
- Veröffentlicht 23.10.2008 22:00:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the pro...
CVE-2008-4582
- EPSS 35.58%
- Veröffentlicht 15.10.2008 20:08:02
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the...
- EPSS 6.57%
- Veröffentlicht 29.09.2008 20:09:59
- Zuletzt bearbeitet 09.04.2025 00:30:58
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and...
- EPSS 44.68%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.
CVE-2008-3835
- EPSS 0.12%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vect...
CVE-2008-3836
- EPSS 2.94%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _in...
CVE-2008-3837
- EPSS 3.67%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted...
CVE-2008-4058
- EPSS 3.48%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 09.04.2025 00:30:58
The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vec...