Mozilla

Firefox

3102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 21%
  • Veröffentlicht 26.02.2007 19:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Multiple unspecified vulnerabilities in the layout engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allow remote attackers to cause a denial of service (crash) and potentially e...

  • EPSS 30.97%
  • Veröffentlicht 26.02.2007 19:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to execute arbitrary code via a large stroke-width attribute in the clip...

  • EPSS 42.76%
  • Veröffentlicht 26.02.2007 19:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vect...

  • EPSS 2.18%
  • Veröffentlicht 26.02.2007 19:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.

Exploit
  • EPSS 21.38%
  • Veröffentlicht 26.02.2007 17:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize h...

  • EPSS 4.42%
  • Veröffentlicht 26.02.2007 17:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site t...

  • EPSS 0.61%
  • Veröffentlicht 23.02.2007 02:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy by tricking a user into saving a bookmarklet with a data: scheme, which is executed in the context of...

  • EPSS 0.91%
  • Veröffentlicht 20.02.2007 02:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.

Exploit
  • EPSS 16.43%
  • Veröffentlicht 16.02.2007 01:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the h...

  • EPSS 9.85%
  • Veröffentlicht 13.02.2007 11:28:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability ...