Mozilla

Firefox

2996 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 13.71%
  • Veröffentlicht 20.12.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers ...

  • EPSS 37.53%
  • Veröffentlicht 20.12.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting...

  • EPSS 28.74%
  • Veröffentlicht 20.12.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.

  • EPSS 25.73%
  • Veröffentlicht 20.12.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown ...

  • EPSS 17.11%
  • Veröffentlicht 20.12.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: ...

  • EPSS 41.55%
  • Veröffentlicht 20.12.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending an SVG comment DOM node to another type of document, which triggers memory corruption.

Exploit
  • EPSS 3.17%
  • Veröffentlicht 20.12.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requesting favicon.ico icons, which results in a privacy leak that might allow feed viewing services to determine browsing habits.

  • EPSS 6.08%
  • Veröffentlicht 20.12.2006 01:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype regression error.

  • EPSS 0.46%
  • Veröffentlicht 15.12.2006 19:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated ...

Exploit
  • EPSS 3.06%
  • Veröffentlicht 24.11.2006 17:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions, do not properly verify that an ACTION URL in a FORM element containing a password INPUT element matc...