Mozilla

Firefox

3280 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.11%
  • Veröffentlicht 18.04.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:11:42

The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.

  • EPSS 1.8%
  • Veröffentlicht 25.03.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:11:23

Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.

  • EPSS 1.42%
  • Veröffentlicht 25.03.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:11:24

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.

  • EPSS 3.86%
  • Veröffentlicht 25.03.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:11:24

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string t...

  • EPSS 1.01%
  • Veröffentlicht 23.03.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:10:35

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

  • EPSS 1.66%
  • Veröffentlicht 04.03.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:11:24

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which caus...

Exploit
  • EPSS 20.4%
  • Veröffentlicht 08.02.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:10:44

The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homog...

Exploit
  • EPSS 2.67%
  • Veröffentlicht 07.02.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:10:44

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

  • EPSS 1.04%
  • Veröffentlicht 24.01.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:10:35

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

  • EPSS 8.01%
  • Veröffentlicht 31.12.2004 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:06:38

Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overfl...