CVE-2009-3010
- EPSS 0.39%
- Published 31.08.2009 16:30:06
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting ...
CVE-2009-3014
- EPSS 0.29%
- Published 31.08.2009 16:30:06
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly handle javascript: URIs in HTML links within 302 error documents sent from web servers, which allows user-assisted re...
CVE-2007-4039
- EPSS 0.48%
- Published 27.07.2007 22:30:00
- Last modified 09.04.2025 00:30:58
Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted...
CVE-2007-3144
- EPSS 0.59%
- Published 11.06.2007 18:30:00
- Last modified 09.04.2025 00:30:58
Visual truncation vulnerability in Mozilla 1.7.12 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long hostname, which is truncated after a certain number of characters, as demonstrated by a phishing attac...
- EPSS 3.32%
- Published 02.04.2007 22:19:00
- Last modified 09.04.2025 00:30:58
The Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object that is still being used. NOTE: t...
CVE-2006-6498
- EPSS 11.21%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, SeaMonkey before 1.0.7, and Mozilla 1.7 and probably earlier on Solaris, allow remote attackers to...
CVE-2006-0292
- EPSS 10.39%
- Published 02.02.2006 20:06:00
- Last modified 03.04.2025 01:03:51
The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garb...
CVE-2006-0496
- EPSS 11.45%
- Published 01.02.2006 02:02:00
- Last modified 03.04.2025 01:03:51
Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (C...
CVE-2005-4685
- EPSS 0.34%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote attackers to trick a user into accepting a cookie for a hostname formed via search-list expansion of ...
- EPSS 10.38%
- Published 31.12.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via an A HREF tag that contains a TABLE tag that contains another A tag.