CVE-2007-0801
- EPSS 0.62%
- Veröffentlicht 07.02.2007 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The nsExternalAppHandler::SetUpTempFile function in Mozilla Firefox 1.5.0.9 creates temporary files with predictable filenames based on creation time, which allows remote attackers to execute arbitrary web script or HTML via a crafted XMLHttpRequest.
CVE-2007-0802
- EPSS 0.97%
- Veröffentlicht 07.02.2007 11:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist ...
CVE-2006-6497
- EPSS 11.21%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and ...
CVE-2006-6498
- EPSS 11.21%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, SeaMonkey before 1.0.7, and Mozilla 1.7 and probably earlier on Solaris, allow remote attackers to...
CVE-2006-6499
- EPSS 13.71%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers ...
CVE-2006-6500
- EPSS 37.53%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting...
CVE-2006-6501
- EPSS 26.24%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
CVE-2006-6502
- EPSS 20.71%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown ...
CVE-2006-6503
- EPSS 10.29%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: ...
CVE-2006-6504
- EPSS 41.55%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.