CVE-2007-4013
- EPSS 1.22%
- Veröffentlicht 26.07.2007 01:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple unspecified vulnerabilities in (1) Net6Helper.DLL (aka Net6Launcher Class) 4.5.2 and earlier, (2) npCtxCAO.dll (aka Citrix Endpoint Analysis Client) in a Firefox plugin directory, and (3) a second npCtxCAO.dll (aka CCAOControl Object) before...
CVE-2007-3734
- EPSS 9.9%
- Veröffentlicht 18.07.2007 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.
CVE-2007-3735
- EPSS 9.06%
- Veröffentlicht 18.07.2007 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.
CVE-2007-3736
- EPSS 2.05%
- Veröffentlicht 18.07.2007 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probab...
CVE-2007-3737
- EPSS 10.03%
- Veröffentlicht 18.07.2007 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privileges by calling an event handler from an unspecified "element outside of a document."
CVE-2007-3738
- EPSS 15.74%
- Veröffentlicht 18.07.2007 17:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.
- EPSS 0.33%
- Veröffentlicht 17.07.2007 21:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.c...
CVE-2007-3656
- EPSS 6.6%
- Veröffentlicht 10.07.2007 19:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further atta...
CVE-2007-3657
- EPSS 0.94%
- Veröffentlicht 10.07.2007 19:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of service by opening multiple tabs in a popup window. NOTE: this issue has been disputed by third party researchers, stating that "this does not crash on me, and I can't see a likely...
CVE-2007-3670
- EPSS 50.12%
- Veröffentlicht 10.07.2007 19:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell m...