- EPSS 0.56%
- Published 15.08.2007 00:17:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the contents of the status bar via a link to a data: URI containing an encoded URL. NOTE: the severity of this issue has been disputed by a reliable third party, since the intended...
CVE-2007-3844
- EPSS 26.71%
- Published 08.08.2007 01:17:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an a...
CVE-2007-3845
- EPSS 43.24%
- Published 08.08.2007 01:17:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the fi...
CVE-2007-4038
- EPSS 0.27%
- Published 27.07.2007 22:30:00
- Last modified 09.04.2025 00:30:58
Argument injection vulnerability in Mozilla Firefox before 2.0.0.5, when running on systems with Thunderbird 1.5 installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands ...
CVE-2007-4041
- EPSS 10.7%
- Published 27.07.2007 22:30:00
- Last modified 09.04.2025 00:30:58
Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharacters in a (1) mailto, (2) nntp, (3) news, (4) snews, or (5) telnet URI,...
CVE-2007-4013
- EPSS 1.17%
- Published 26.07.2007 01:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before...
CVE-2007-3734
- EPSS 14.4%
- Published 18.07.2007 17:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.
CVE-2007-3735
- EPSS 10.32%
- Published 18.07.2007 17:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.
CVE-2007-3736
- EPSS 3.48%
- Published 18.07.2007 17:30:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probab...
CVE-2007-3737
- EPSS 9.68%
- Published 18.07.2007 17:30:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privileges by calling an event handler from an unspecified "element outside of a document."