CVE-2007-3735
- EPSS 10.32%
- Veröffentlicht 18.07.2007 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.
CVE-2007-3736
- EPSS 2.61%
- Veröffentlicht 18.07.2007 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probab...
CVE-2007-3737
- EPSS 9.68%
- Veröffentlicht 18.07.2007 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privileges by calling an event handler from an unspecified "element outside of a document."
CVE-2007-3738
- EPSS 11.99%
- Veröffentlicht 18.07.2007 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
- EPSS 0.27%
- Veröffentlicht 17.07.2007 21:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.c...
CVE-2007-3656
- EPSS 5.23%
- Veröffentlicht 10.07.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further atta...
CVE-2007-3657
- EPSS 0.78%
- Veröffentlicht 10.07.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of service by opening multiple tabs in a popup window. NOTE: this issue has been disputed by third party researchers, stating that "this does not crash on me, and I can't see a likely...
CVE-2007-3670
- EPSS 49.73%
- Veröffentlicht 10.07.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell m...
CVE-2007-3511
- EPSS 3.38%
- Veröffentlicht 03.07.2007 10:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which ...
CVE-2007-3285
- EPSS 1.88%
- Veröffentlicht 20.06.2007 19:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extens...