CVE-2006-6506
- EPSS 2.55%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requesting favicon.ico icons, which results in a privacy leak that might allow feed viewing services to determine browsing habits.
CVE-2006-6507
- EPSS 4.31%
- Veröffentlicht 20.12.2006 01:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype regression error.
CVE-2006-6585
- EPSS 0.46%
- Veröffentlicht 15.12.2006 19:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated ...
- EPSS 3.06%
- Veröffentlicht 24.11.2006 17:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matc...
CVE-2006-5463
- EPSS 9.1%
- Veröffentlicht 08.11.2006 22:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary JavaScript bytecode via unspecified vectors involving modification of a Script object whi...
CVE-2006-5462
- EPSS 12.79%
- Veröffentlicht 08.11.2006 21:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6, when using an RSA key with exponent 3, does not properly handle extra data in a signature...
- EPSS 22.09%
- Veröffentlicht 08.11.2006 21:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) via unspecified vectors.
CVE-2006-5747
- EPSS 12.45%
- Veröffentlicht 08.11.2006 21:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execute arbitrary code via the XML.prototype.hasOwnProperty JavaScript function.
- EPSS 12.33%
- Veröffentlicht 08.11.2006 21:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code vi...
CVE-2006-5783
- EPSS 0.87%
- Veröffentlicht 07.11.2006 23:07:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Firefox 1.5.0.7 on Kubuntu Linux allows remote attackers to cause a denial of service (crash) via a long URL in an A tag. NOTE: this issue has been disputed by several vendors, who could not reproduce the report. In addition, the scope of the impact...