CVE-2007-1256
- EPSS 0.81%
- Veröffentlicht 03.03.2007 20:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to anoth...
CVE-2007-0996
- EPSS 2.51%
- Veröffentlicht 27.02.2007 02:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent window, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated us...
- EPSS 0.55%
- Veröffentlicht 26.02.2007 23:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.
CVE-2007-0008
- EPSS 17.42%
- Veröffentlicht 26.02.2007 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server produc...
CVE-2007-0009
- EPSS 49.54%
- Veröffentlicht 26.02.2007 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System ser...
CVE-2007-0778
- EPSS 1.08%
- Veröffentlicht 26.02.2007 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive i...
CVE-2007-0779
- EPSS 3.39%
- Veröffentlicht 26.02.2007 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoof certain user interface elements, such as the host name or security indicators, via the CSS3 hotspot...
CVE-2007-0780
- EPSS 2.16%
- Veröffentlicht 26.02.2007 20:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked...
CVE-2007-0775
- EPSS 21%
- Veröffentlicht 26.02.2007 19:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially e...
CVE-2007-0776
- EPSS 30.97%
- Veröffentlicht 26.02.2007 19:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clip...