Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 9.16%
  • Veröffentlicht 02.06.2006 20:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.

  • EPSS 23.29%
  • Veröffentlicht 02.06.2006 19:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented...

  • EPSS 26.53%
  • Veröffentlicht 02.06.2006 19:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption.

  • EPSS 1.44%
  • Veröffentlicht 02.06.2006 19:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.

  • EPSS 4.98%
  • Veröffentlicht 02.06.2006 19:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the mi...

  • EPSS 3.98%
  • Veröffentlicht 02.06.2006 19:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascrip...

  • EPSS 2.01%
  • Veröffentlicht 02.06.2006 19:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5.0.4 allows user-assisted remote attackers to inject arbitrary web script or HTML by tricking a user into (1) performing a "View Image" on a broken image in which the SRC attribute...

  • EPSS 7.93%
  • Veröffentlicht 02.06.2006 18:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allow remote attackers to bypass restrictions by causing a persisted string to be associated with the wro...

  • EPSS 31.16%
  • Veröffentlicht 02.06.2006 18:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.

  • EPSS 35.11%
  • Veröffentlicht 02.06.2006 18:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Unspecified vulnerability in Mozilla Firefox before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to execute arbitrary code by using the nsISelectionPrivate interface of the Selection object to add a SelectionListener and create notifica...