CVE-2014-1504
- EPSS 0.61%
- Published 19.03.2014 10:55:06
- Last modified 12.04.2025 10:46:40
The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted ...
CVE-2013-4002
- EPSS 1.42%
- Published 23.07.2013 11:03:19
- Last modified 11.04.2025 00:51:21
XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Ja...
CVE-2012-4180
- EPSS 9.49%
- Published 10.10.2012 17:55:02
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in the nsHTMLEditor::IsPrevCharInNodeWhitespace function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote a...
CVE-2012-4188
- EPSS 55.61%
- Published 10.10.2012 17:55:02
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in the Convolve3x3 function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary...
CVE-2012-4187
- EPSS 24.84%
- Published 10.10.2012 17:55:02
- Last modified 11.04.2025 00:51:21
Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly manage a certain insPos variable, which allows remote attackers to execute arbitrary c...
CVE-2012-4186
- EPSS 55.61%
- Published 10.10.2012 17:55:02
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in the nsWaveReader::DecodeAudioData function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to...
CVE-2012-4185
- EPSS 5.23%
- Published 10.10.2012 17:55:02
- Last modified 11.04.2025 00:51:21
Buffer overflow in the nsCharTraits::length function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to execute arbitrary c...
CVE-2012-4184
- EPSS 1.1%
- Published 10.10.2012 17:55:02
- Last modified 11.04.2025 00:51:21
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not prevent access to properties of a prototype...
CVE-2012-4183
- EPSS 2.72%
- Published 10.10.2012 17:55:02
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the DOMSVGTests::GetRequiredFeatures function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attacke...
CVE-2012-4182
- EPSS 4.75%
- Published 10.10.2012 17:55:02
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the nsTextEditRules::WillInsert function in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to...