CVE-2008-0415
- EPSS 1.48%
- Veröffentlicht 08.02.2008 22:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.lo...
CVE-2008-0417
- EPSS 1.86%
- Veröffentlicht 08.02.2008 22:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.
CVE-2008-0418
- EPSS 38.66%
- Veröffentlicht 08.02.2008 22:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome:...
CVE-2008-0419
- EPSS 18.69%
- Veröffentlicht 08.02.2008 22:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) via images in a page that uses designMode frames, which triggers memory corruption related to resize ...
- EPSS 0.65%
- Veröffentlicht 19.01.2008 00:00:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing...
CVE-2007-6589
- EPSS 0.55%
- Veröffentlicht 28.12.2007 21:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 does not update the origin domain when retrieving the inner URL parameter yields an HTTP redirect, which allows remote attackers to conduct cross-site scripting (X...
CVE-2007-5959
- EPSS 13.31%
- Veröffentlicht 26.11.2007 23:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger memory corruption.
CVE-2007-5960
- EPSS 0.93%
- Veröffentlicht 26.11.2007 23:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer...
CVE-2007-5947
- EPSS 7.92%
- Veröffentlicht 14.11.2007 01:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remot...
CVE-2007-5896
- EPSS 0.62%
- Veröffentlicht 08.11.2007 20:46:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3) fi...