CVE-2008-1236
- EPSS 3.37%
- Veröffentlicht 27.03.2008 10:44:00
- Zuletzt bearbeitet 16.06.2026 22:51:19
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors relat...
CVE-2008-1237
- EPSS 3.37%
- Veröffentlicht 27.03.2008 10:44:00
- Zuletzt bearbeitet 16.06.2026 22:51:19
Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors relat...
CVE-2008-0304
- EPSS 6.05%
- Veröffentlicht 29.02.2008 19:44:00
- Zuletzt bearbeitet 16.06.2026 22:49:21
Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation ...
CVE-2008-0416
- EPSS 1.62%
- Veröffentlicht 12.02.2008 03:00:00
- Zuletzt bearbeitet 16.06.2026 22:49:35
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including ...
CVE-2008-0420
- EPSS 2.22%
- Veröffentlicht 12.02.2008 03:00:00
- Zuletzt bearbeitet 16.06.2026 22:49:36
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to re...
CVE-2008-0591
- EPSS 3.85%
- Veröffentlicht 09.02.2008 00:00:00
- Zuletzt bearbeitet 16.06.2026 22:49:56
Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by...
CVE-2008-0412
- EPSS 3.3%
- Veröffentlicht 08.02.2008 22:00:00
- Zuletzt bearbeitet 16.06.2026 22:49:33
The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableF...
CVE-2008-0413
- EPSS 2.48%
- Veröffentlicht 08.02.2008 22:00:00
- Zuletzt bearbeitet 16.06.2026 22:49:34
The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via (1) a large switch statement, (2...
CVE-2008-0415
- EPSS 2.21%
- Veröffentlicht 08.02.2008 22:00:00
- Zuletzt bearbeitet 16.06.2026 22:49:34
Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.lo...
CVE-2008-0418
- EPSS 8.63%
- Veröffentlicht 08.02.2008 22:00:00
- Zuletzt bearbeitet 16.06.2026 22:49:35
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome:...