CVE-2005-0592
- EPSS 3.41%
- Published 25.03.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string t...
CVE-2005-0143
- EPSS 0.77%
- Published 23.03.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
CVE-2005-0593
- EPSS 1.25%
- Published 04.03.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which caus...
- EPSS 1.2%
- Published 15.02.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail me...
CVE-2005-0233
- EPSS 8.58%
- Published 08.02.2005 05:00:00
- Last modified 03.04.2025 01:03:51
The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homog...
- EPSS 18.83%
- Published 27.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send p...
- EPSS 18.83%
- Published 27.01.2005 05:00:00
- Last modified 03.04.2025 01:03:51
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachment...
- EPSS 31.75%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overfl...
CVE-2004-0906
- EPSS 0.14%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
The XPInstall installer in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 sets insecure permissions for certain installed files within xpi packages, which could allow local users to overwrite arbitrary fi...
CVE-2004-0907
- EPSS 0.1%
- Published 31.12.2004 05:00:00
- Last modified 03.04.2025 01:03:51
The Linux install .tar.gz archives for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8, create certain files with insecure permissions, which could allow local users to overwrite those files and execute ar...