CVE-2008-1235
- EPSS 19.12%
- Published 27.03.2008 10:44:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via unknown vectors that cause JavaScript to execute with the wrong principal, aka...
CVE-2008-1236
- EPSS 28.84%
- Published 27.03.2008 10:44:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors relat...
CVE-2008-1237
- EPSS 28.84%
- Published 27.03.2008 10:44:00
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors relat...
CVE-2008-0304
- EPSS 33.52%
- Published 29.02.2008 19:44:00
- Last modified 09.04.2025 00:30:58
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation ...
CVE-2008-0416
- EPSS 6.63%
- Published 12.02.2008 03:00:00
- Last modified 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including ...
CVE-2008-0420
- EPSS 2.1%
- Published 12.02.2008 03:00:00
- Last modified 09.04.2025 00:30:58
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to re...
CVE-2008-0591
- EPSS 6.22%
- Published 09.02.2008 00:00:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by...
CVE-2008-0412
- EPSS 8.85%
- Published 08.02.2008 22:00:00
- Last modified 09.04.2025 00:30:58
The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableF...
CVE-2008-0413
- EPSS 6.09%
- Published 08.02.2008 22:00:00
- Last modified 09.04.2025 00:30:58
The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via (1) a large switch statement, (2...
CVE-2008-0415
- EPSS 1.48%
- Published 08.02.2008 22:00:00
- Last modified 09.04.2025 00:30:58
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.lo...