CVE-2010-2767
- EPSS 4.76%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow ...
CVE-2010-2768
- EPSS 0.77%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote...
CVE-2010-2769
- EPSS 1.27%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML...
CVE-2010-2770
- EPSS 2.94%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly ex...
CVE-2010-3166
- EPSS 5.96%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute ar...
CVE-2010-3167
- EPSS 5.4%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to e...
CVE-2010-3168
- EPSS 5.4%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict the role of property changes in triggering XUL tree removal, which allows remote attackers to c...
CVE-2010-3169
- EPSS 3.23%
- Veröffentlicht 09.09.2010 19:00:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allow remote attackers to cause a denial of service (memor...
CVE-2010-3131
- EPSS 10.23%
- Veröffentlicht 26.08.2010 18:36:35
- Zuletzt bearbeitet 29.04.2026 01:13:23
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbit...
CVE-2010-2751
- EPSS 0.36%
- Veröffentlicht 30.07.2010 20:30:02
- Zuletzt bearbeitet 29.04.2026 01:13:23
The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vecto...