- EPSS 0.21%
- Published 22.02.2010 13:00:01
- Last modified 11.04.2025 00:51:21
Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-s...
CVE-2010-0654
- EPSS 0.7%
- Published 18.02.2010 18:00:00
- Last modified 11.04.2025 00:51:21
Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 permit cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type ...
- EPSS 0.25%
- Published 29.01.2010 18:30:00
- Last modified 11.04.2025 00:51:21
Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or APP_TYPE_EDITOR, which makes it easier for remote attackers to determine the network location of the a...
- EPSS 0.23%
- Published 29.01.2010 18:30:00
- Last modified 11.04.2025 00:51:21
Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML documents, which makes it easier for remote attackers to determine the network location of the applica...
CVE-2009-3388
- EPSS 2.63%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to "memory safety issues."
CVE-2009-3389
- EPSS 5.53%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a vid...
CVE-2009-3979
- EPSS 3.19%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) ...
CVE-2009-3980
- EPSS 4.41%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execut...
CVE-2009-3981
- EPSS 3.87%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
CVE-2009-3982
- EPSS 8.29%
- Published 17.12.2009 17:30:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exe...