CVE-2006-3806
- EPSS 29.56%
- Veröffentlicht 27.07.2006 19:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple integer overflows in the Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving (1) long strings in the toSourc...
CVE-2006-3807
- EPSS 27.49%
- Veröffentlicht 27.07.2006 19:04:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code via script that changes the standard Object() constructor to return a reference to a privileged object and callin...
CVE-2006-2786
- EPSS 2.44%
- Veröffentlicht 02.06.2006 20:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
HTTP response smuggling vulnerability in Mozilla Firefox and Thunderbird before 1.5.0.4, when used with certain proxy servers, allows remote attackers to cause Firefox to interpret certain responses as if they were responses from two different sites ...
CVE-2006-2787
- EPSS 9.16%
- Veröffentlicht 02.06.2006 20:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf method on objects that were created outside of the sandbox.
CVE-2006-2779
- EPSS 23.29%
- Veröffentlicht 02.06.2006 19:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented...
CVE-2006-2780
- EPSS 26.53%
- Veröffentlicht 02.06.2006 19:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption.
CVE-2006-2781
- EPSS 7.24%
- Veröffentlicht 02.06.2006 19:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Double free vulnerability in nsVCard.cpp in Mozilla Thunderbird before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a VCard that contains invalid base64 charact...
CVE-2006-2783
- EPSS 4.98%
- Veröffentlicht 02.06.2006 19:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the mi...
CVE-2006-2775
- EPSS 7.93%
- Veröffentlicht 02.06.2006 18:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allow remote attackers to bypass restrictions by causing a persisted string to be associated with the wro...
CVE-2006-2776
- EPSS 31.16%
- Veröffentlicht 02.06.2006 18:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.