- EPSS 13.99%
- Published 14.04.2006 10:02:00
- Last modified 03.04.2025 01:03:51
The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remot...
- EPSS 0.38%
- Published 06.04.2006 10:04:00
- Last modified 03.04.2025 01:03:51
Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockwave Flash application, then changing the window location back to a trusted URL while the Flash applic...
CVE-2006-1273
- EPSS 1.15%
- Published 19.03.2006 11:06:00
- Last modified 03.04.2025 01:03:51
Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action handlers such as onload and onmouseover, which triggers the crash when the user views the page source....
CVE-2006-0299
- EPSS 1.28%
- Published 02.02.2006 23:06:00
- Last modified 03.04.2025 01:03:51
The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the internal "AnyName" object to external interfaces, which allows multiple cooperating domains to exchange info...
CVE-2006-0297
- EPSS 10.03%
- Published 02.02.2006 22:02:00
- Last modified 03.04.2025 01:03:51
Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the (1) EscapeAttributeValue in jsxml.c for E4X, (2) nsSVGCairoSu...
CVE-2006-0298
- EPSS 5.92%
- Published 02.02.2006 22:02:00
- Last modified 03.04.2025 01:03:51
The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly read sensitive data via unknown attack vectors that trigger an out-of-bounds read.
CVE-2006-0292
- EPSS 10.39%
- Published 02.02.2006 20:06:00
- Last modified 03.04.2025 01:03:51
The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garb...
CVE-2006-0293
- EPSS 3.72%
- Published 02.02.2006 20:06:00
- Last modified 03.04.2025 01:03:51
The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that opera...
CVE-2006-0294
- EPSS 7.64%
- Published 02.02.2006 20:06:00
- Last modified 03.04.2025 01:03:51
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to o...
CVE-2006-0295
- EPSS 82.37%
- Published 02.02.2006 20:06:00
- Last modified 03.04.2025 01:03:51
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory...