CVE-2009-1232
- EPSS 17%
- Veröffentlicht 02.04.2009 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 3.0...
CVE-2009-1169
- EPSS 35.96%
- Veröffentlicht 27.03.2009 00:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT trans...
CVE-2009-0581
- EPSS 1.89%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 09.04.2025 00:30:58
Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.
CVE-2009-0723
- EPSS 0.86%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer over...
CVE-2009-0733
- EPSS 1.6%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image ...
CVE-2009-1044
- EPSS 7.84%
- Veröffentlicht 23.03.2009 14:19:12
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils duri...
- EPSS 7.68%
- Veröffentlicht 05.03.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption a...
CVE-2009-0772
- EPSS 7.32%
- Veröffentlicht 05.03.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetO...
- EPSS 9.17%
- Veröffentlicht 05.03.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some...
CVE-2009-0774
- EPSS 7.46%
- Veröffentlicht 05.03.2009 02:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different v...