CVE-2006-0293
- EPSS 3.74%
- Veröffentlicht 02.02.2006 20:06:00
- Zuletzt bearbeitet 16.06.2026 22:20:16
The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that opera...
CVE-2006-0294
- EPSS 4.93%
- Veröffentlicht 02.02.2006 20:06:00
- Zuletzt bearbeitet 16.06.2026 22:20:16
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to o...
CVE-2006-0295
- EPSS 71.31%
- Veröffentlicht 02.02.2006 20:06:00
- Zuletzt bearbeitet 16.06.2026 22:20:17
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory...
- EPSS 4.14%
- Veröffentlicht 02.02.2006 20:06:00
- Zuletzt bearbeitet 16.06.2026 22:20:17
The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf fil...
CVE-2006-0496
- EPSS 2.67%
- Veröffentlicht 01.02.2006 02:02:00
- Zuletzt bearbeitet 16.06.2026 22:20:43
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (C...
CVE-2005-4685
- EPSS 1.18%
- Veröffentlicht 31.12.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:19:14
Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of ...
- EPSS 8.41%
- Veröffentlicht 31.12.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:19:18
Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large value of the WIDTH attribute, which triggers a problem related to representation of floating-point numbe...
- EPSS 6.02%
- Veröffentlicht 31.12.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:19:29
Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.
- EPSS 12.59%
- Veröffentlicht 09.12.2005 15:03:00
- Zuletzt bearbeitet 16.06.2026 22:18:13
Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and delayed application startup) via a web site with a large title, which is recorded in history.dat but not...
CVE-2005-3089
- EPSS 1.68%
- Veröffentlicht 28.09.2005 18:03:00
- Zuletzt bearbeitet 16.06.2026 22:16:13
Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnera...