- EPSS 5.78%
- Veröffentlicht 15.09.2006 19:07:00
- Zuletzt bearbeitet 16.06.2026 22:29:22
Multiple unspecified vulnerabilities in Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allow remote attackers to cause a denial of service (crash), corrupt memory, and possibly execute arbitrary code via unspecified ve...
- EPSS 2.28%
- Veröffentlicht 15.09.2006 18:07:00
- Zuletzt bearbeitet 16.06.2026 22:28:54
Mozilla Network Security Service (NSS) library before 3.11.3, as used in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5, when using an RSA key with exponent 3, does not properly handle extra data in a signature...
CVE-2006-4565
- EPSS 6.06%
- Veröffentlicht 15.09.2006 18:07:00
- Zuletzt bearbeitet 16.06.2026 22:29:20
Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression ...
- EPSS 4%
- Veröffentlicht 15.09.2006 18:07:00
- Zuletzt bearbeitet 16.06.2026 22:29:21
Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) via a malformed JavaScript regular expression that ends with a backslash in an unterminated character ...
CVE-2006-4567
- EPSS 1.9%
- Veröffentlicht 15.09.2006 18:07:00
- Zuletzt bearbeitet 16.06.2026 22:29:21
Mozilla Firefox before 1.5.0.7 and Thunderbird before 1.5.0.7 makes it easy for users to accept self-signed certificates for the auto-update mechanism, which might allow remote user-assisted attackers to use DNS spoofing to trick users into visiting ...
CVE-2006-3812
- EPSS 3.09%
- Veröffentlicht 29.07.2006 00:04:00
- Zuletzt bearbeitet 16.06.2026 22:27:52
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to reference remote files and possibly load chrome: URLs by tricking the user into copying or dragging links.
CVE-2006-3113
- EPSS 6.31%
- Veröffentlicht 27.07.2006 20:04:00
- Zuletzt bearbeitet 16.06.2026 22:26:25
Mozilla Firefox 1.5 before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via simultaneous XPCOM events, which causes a timer object to ...
CVE-2006-3802
- EPSS 2.32%
- Veröffentlicht 27.07.2006 20:04:00
- Zuletzt bearbeitet 16.06.2026 22:27:50
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows remote attackers to hijack native DOM methods from objects in another domain and conduct cross-site scripting (XSS) attacks using DOM methods of the top-lev...
CVE-2006-3805
- EPSS 6.48%
- Veröffentlicht 27.07.2006 20:04:00
- Zuletzt bearbeitet 16.06.2026 22:27:51
The Javascript engine in Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 might allow remote attackers to execute arbitrary code via vectors involving garbage collection that causes deletion of a temporary object...
CVE-2006-3809
- EPSS 3.04%
- Veröffentlicht 27.07.2006 20:04:00
- Zuletzt bearbeitet 16.06.2026 22:27:52
Mozilla Firefox before 1.5.0.5, Thunderbird before 1.5.0.5, and SeaMonkey before 1.0.3 allows scripts with the UniversalBrowserRead privilege to gain UniversalXPConnect privileges and possibly execute code or obtain sensitive data by reading into a p...