Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 16.08%
  • Veröffentlicht 31.10.2006 22:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment o...

  • EPSS 7.26%
  • Veröffentlicht 05.10.2006 04:04:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving JavaScript. NOTE: the vendor and original researchers have released a follow-up comment disputing the severity of this...

  • EPSS 0.45%
  • Veröffentlicht 05.10.2006 04:04:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher st...

  • EPSS 0.88%
  • Veröffentlicht 15.09.2006 19:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other atta...

  • EPSS 2.73%
  • Veröffentlicht 15.09.2006 19:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduc...

  • EPSS 4.51%
  • Veröffentlicht 15.09.2006 18:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature...

  • EPSS 10.07%
  • Veröffentlicht 15.09.2006 18:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression ...

  • EPSS 18.7%
  • Veröffentlicht 15.09.2006 18:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character ...

Exploit
  • EPSS 2.27%
  • Veröffentlicht 15.09.2006 18:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting ...

Exploit
  • EPSS 1.05%
  • Veröffentlicht 06.09.2006 00:04:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet web server, by hosting script on an Internet web server that can be made inaccessible by the attacker a...