Mozilla

Firefox

3102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 5.66%
  • Veröffentlicht 22.04.2009 18:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header or...

Exploit
  • EPSS 16.03%
  • Veröffentlicht 02.04.2009 17:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-tags with no corresponding end-tags. NOTE: it was later reported that 3.0...

Exploit
  • EPSS 37.5%
  • Veröffentlicht 27.03.2009 00:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT trans...

Exploit
  • EPSS 1.89%
  • Veröffentlicht 23.03.2009 14:19:12
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.

Exploit
  • EPSS 0.86%
  • Veröffentlicht 23.03.2009 14:19:12
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer over...

Exploit
  • EPSS 1.87%
  • Veröffentlicht 23.03.2009 14:19:12
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image ...

  • EPSS 7.84%
  • Veröffentlicht 23.03.2009 14:19:12
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils duri...

  • EPSS 7.68%
  • Veröffentlicht 05.03.2009 02:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption a...

  • EPSS 7.32%
  • Veröffentlicht 05.03.2009 02:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetO...

Exploit
  • EPSS 9.17%
  • Veröffentlicht 05.03.2009 02:30:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some...