Mozilla

Thunderbird

1584 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 19.73%
  • Veröffentlicht 09.11.2011 11:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle links from SVG mpath elements to non-SVG elements, which allows remote attackers to cause a denial of service (memory corruption and application cras...

  • EPSS 0.43%
  • Veröffentlicht 29.09.2011 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent the starting of a download in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended ac...

  • EPSS 1.98%
  • Veröffentlicht 29.09.2011 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application cra...

  • EPSS 3.14%
  • Veröffentlicht 29.09.2011 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitr...

  • EPSS 0.72%
  • Veröffentlicht 29.09.2011 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a diffe...

  • EPSS 1.3%
  • Veröffentlicht 29.09.2011 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote a...

  • EPSS 0.2%
  • Veröffentlicht 29.09.2011 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions ...

  • EPSS 3.36%
  • Veröffentlicht 29.09.2011 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OGG headers in a ....

  • EPSS 4.66%
  • Veröffentlicht 29.09.2011 00:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.

  • EPSS 4.11%
  • Veröffentlicht 18.08.2011 18:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, ...