- EPSS 12.33%
- Veröffentlicht 08.11.2006 21:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code vi...
CVE-2006-5783
- EPSS 1.42%
- Veröffentlicht 07.11.2006 23:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Firefox 1.5.0.7 on Kubuntu Linux allows remote attackers to cause a denial of service (crash) via a long URL in an A tag. NOTE: this issue has been disputed by several vendors, who could not reproduce the report. In addition, the scope of the impact...
- EPSS 19.79%
- Veröffentlicht 31.10.2006 22:07:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment o...
CVE-2006-5159
- EPSS 7.26%
- Veröffentlicht 05.10.2006 04:04:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving JavaScript. NOTE: the vendor and original researchers have released a follow-up comment disputing the severity of this...
CVE-2006-5160
- EPSS 0.45%
- Veröffentlicht 05.10.2006 04:04:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher st...
CVE-2006-4568
- EPSS 1.36%
- Veröffentlicht 15.09.2006 19:07:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other atta...
CVE-2006-4569
- EPSS 2.2%
- Veröffentlicht 15.09.2006 19:07:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduc...
- EPSS 2.7%
- Veröffentlicht 15.09.2006 18:07:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature...
CVE-2006-4565
- EPSS 10.37%
- Veröffentlicht 15.09.2006 18:07:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression ...
- EPSS 24.71%
- Veröffentlicht 15.09.2006 18:07:00
- Zuletzt bearbeitet 16.04.2026 00:27:16
Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character ...