CVE-2007-3511
- EPSS 4.48%
- Veröffentlicht 03.07.2007 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The focus handling for the onkeydown event in Mozilla Firefox 1.5.0.12, 2.0.0.4 and other versions before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to change field focus and copy keystrokes via the "for" attribute in a label, which ...
CVE-2007-3285
- EPSS 1.96%
- Veröffentlicht 20.06.2007 19:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extens...
CVE-2007-3089
- EPSS 25.28%
- Veröffentlicht 06.06.2007 21:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript cod...
CVE-2007-3072
- EPSS 0.65%
- Veröffentlicht 06.06.2007 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.
CVE-2007-3073
- EPSS 1.48%
- Veröffentlicht 06.06.2007 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI.
CVE-2007-3074
- EPSS 0.62%
- Veröffentlicht 06.06.2007 10:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.
CVE-2007-1362
- EPSS 46.5%
- Veröffentlicht 01.06.2007 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to cause a denial of service via (1) a large cookie path parameter, which triggers memory consumption, or (2) an internal delimiter w...
CVE-2007-2867
- EPSS 18.5%
- Veröffentlicht 01.06.2007 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of servic...
CVE-2007-2868
- EPSS 27.66%
- Veröffentlicht 01.06.2007 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of se...
CVE-2007-2869
- EPSS 16.44%
- Veröffentlicht 01.06.2007 00:30:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in...