Mozilla

Seamonkey

704 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.69%
  • Published 26.11.2007 23:46:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 sets the Referer header to the window or frame in which script is running, instead of the address of the content that initiated the script, which allows remote attackers to spoof HTTP Referer...

  • EPSS 7.92%
  • Published 14.11.2007 01:46:00
  • Last modified 09.04.2025 00:30:58

The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remot...

  • EPSS 11.56%
  • Published 21.10.2007 20:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 can hide the window's titlebar when displaying XUL markup language documents, which makes it easier for remote attackers to conduct phishing and spoofing attacks by setting the hidechrome attr...

  • EPSS 1.38%
  • Published 21.10.2007 20:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5, when running on Linux systems with gnome-vfs support, might allow remote attackers to read arbitrary files on SSH/sftp servers that accept key authentication by creating a web page on the tar...

  • EPSS 3.3%
  • Published 21.10.2007 20:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Script object to modify XPCNativeWrappers in a way that causes the script to be executed when a chrome ...

  • EPSS 20.18%
  • Published 21.10.2007 19:17:00
  • Last modified 09.04.2025 00:30:58

Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.

  • EPSS 14.75%
  • Published 21.10.2007 19:17:00
  • Last modified 09.04.2025 00:30:58

Multiple vulnerabilities in the Javascript engine in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption.

  • EPSS 1.43%
  • Published 13.09.2007 18:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction, and automatically sends these certificates when requested, which makes it easier for remote web site...

  • EPSS 8.93%
  • Published 12.09.2007 20:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1) mailto, (2) nntp, (3) news, or (4) snews URI with invalid "%" encoding, related to improper file ty...

Exploit
  • EPSS 26.71%
  • Published 08.08.2007 01:17:00
  • Last modified 09.04.2025 00:30:58

Mozilla Firefox 2.0.0.5, Thunderbird 2.0.0.5 and before 1.5.0.13, and SeaMonkey 1.1.3 allows remote attackers to conduct cross-site scripting (XSS) attacks with chrome privileges via an addon that inserts a (1) javascript: or (2) data: link into an a...