- EPSS 8.43%
- Published 07.07.2008 23:41:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unk...
CVE-2008-2802
- EPSS 6.8%
- Published 07.07.2008 23:41:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via an XUL document that includes a script from a chrome: URI that points to a fastload file, related to t...
CVE-2008-2803
- EPSS 6.39%
- Published 07.07.2008 23:41:00
- Last modified 09.04.2025 00:30:58
The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non...
CVE-2008-2806
- EPSS 0.92%
- Published 07.07.2008 23:41:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java Liv...
CVE-2008-2808
- EPSS 2.08%
- Published 07.07.2008 23:41:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted ...
- EPSS 26.86%
- Published 07.07.2008 23:41:00
- Last modified 09.04.2025 00:30:58
The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose di...
CVE-2008-2785
- EPSS 9.52%
- Published 19.06.2008 21:41:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which all...
CVE-2008-1380
- EPSS 19.14%
- Published 17.04.2008 19:05:00
- Last modified 09.04.2025 00:30:58
The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a denial of service (garbage collector crash) and possibly have other impacts via a crafted web page. ...
CVE-2008-1233
- EPSS 22.23%
- Published 27.03.2008 10:44:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via "XPCNativeWrapper pollution."
CVE-2008-1234
- EPSS 8.25%
- Published 27.03.2008 10:44:00
- Last modified 09.04.2025 00:30:58
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event han...