CVE-2007-0995
- EPSS 1.5%
- Published 26.02.2007 19:28:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 ignores trailing invalid HTML characters in attribute names, which allows remote attackers to bypass content filters that use regular expressions.
CVE-2007-1092
- EPSS 28.54%
- Published 26.02.2007 17:28:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers that modify the structure of a document, wich triggers memory corruption due to the lack of a finalize h...
CVE-2007-1095
- EPSS 2.97%
- Published 26.02.2007 17:28:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to run certain JavaScript code and access the location DOM hierarchy in the context of the next web site t...
CVE-2007-0981
- EPSS 18.02%
- Published 16.02.2007 01:28:00
- Last modified 09.04.2025 00:30:58
Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the h...
CVE-2006-6497
- EPSS 11.21%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and ...
CVE-2006-6498
- EPSS 11.21%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, SeaMonkey before 1.0.7, and Mozilla 1.7 and probably earlier on Solaris, allow remote attackers to...
CVE-2006-6499
- EPSS 13.71%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 overwrites memory instead of exiting when the floating point precision is reduced, which allows remote attackers ...
CVE-2006-6500
- EPSS 37.53%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by setting...
CVE-2006-6501
- EPSS 26.24%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to gain privileges and install malicious code via the watch Javascript function.
CVE-2006-6502
- EPSS 20.71%
- Published 20.12.2006 01:28:00
- Last modified 09.04.2025 00:30:58
Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown ...