Mozilla

Thunderbird

1542 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.64%
  • Published 13.07.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been disabled, which makes it easier for remote attackers to bypass such protection.

  • EPSS 0.06%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. conten...

  • EPSS 0.49%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer and may expose the Thunderbird user to vulnerabilities in the version of Internet Explorer that is in...

  • EPSS 8%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not properly check the return values of other functions that resize the string, which allows remote attackers ...

  • EPSS 41.28%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other applications that use the same library, allows remote attackers to execute arbitrary code via a GIF image with a...

  • EPSS 1.77%
  • Published 02.05.2005 04:00:00
  • Last modified 03.04.2025 01:03:51

The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use InstallTrigger to spoof the hostname of the host performing the installation via a long "user:pass" sequen...

  • EPSS 1.2%
  • Published 15.02.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow remote attackers to bypass the user's intended privacy and security policy by using cookies in e-mail me...

  • EPSS 18.83%
  • Published 27.01.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send p...

  • EPSS 18.83%
  • Published 27.01.2005 05:00:00
  • Last modified 03.04.2025 01:03:51

Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachment...

  • EPSS 31.75%
  • Published 31.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overfl...