- EPSS 2.96%
- Published 27.09.2008 10:30:03
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to ...
CVE-2008-3835
- EPSS 0.14%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vect...
CVE-2008-4058
- EPSS 2.43%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vec...
CVE-2008-4060
- EPSS 2%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vector...
- EPSS 2.72%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) ...
- EPSS 2.03%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or po...
CVE-2008-4065
- EPSS 1.31%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) charact...
CVE-2008-4067
- EPSS 1.72%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) ...
CVE-2008-4068
- EPSS 0.19%
- Published 24.09.2008 20:37:04
- Last modified 09.04.2025 00:30:58
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive inf...
- EPSS 9.47%
- Published 07.07.2008 23:41:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unk...