Mozilla

Firefox

3102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.63%
  • Veröffentlicht 12.06.2009 21:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary...

  • EPSS 15.16%
  • Veröffentlicht 12.06.2009 21:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "...

  • EPSS 1.39%
  • Veröffentlicht 12.06.2009 21:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated ...

  • EPSS 4.24%
  • Veröffentlicht 12.06.2009 21:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by t...

  • EPSS 3.74%
  • Veröffentlicht 12.06.2009 21:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to interaction with TinyMCE.

Exploit
  • EPSS 5.95%
  • Veröffentlicht 12.06.2009 21:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image in the BACKGROUND attribute of a BODY element.

Exploit
  • EPSS 12.14%
  • Veröffentlicht 29.05.2009 20:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop."

Exploit
  • EPSS 16.85%
  • Veröffentlicht 29.05.2009 20:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript on...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 11.05.2009 15:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions...

  • EPSS 32.17%
  • Veröffentlicht 30.04.2009 21:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this ...