Vulnerability index

Browse CVEs

99 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Firefox MEDIUM 5.0
CVE-2008-2805

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client compute…

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Firefox HIGH 9.3
CVE-2007-4841

Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1…

Fix: after 2.0.0.8
Fix from $1,950 2007-09-12
Firefox MEDIUM 6.4
CVE-2007-0802

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain nam…

No fix yet
Fix from $1,600 2007-02-07
Firefox MEDIUM 5.0
CVE-2006-6971

Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP…

No fix yet
Fix from $1,600 2007-02-07
Bugzilla MEDIUM 5.5
CVE-2006-0914

Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, whi…

Patch available
Fix from $1,600 2006-02-28
Thunderbird HIGH 9.3
CVE-2006-0884EPSS 7%

The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript securi…

Fix: after 1.0.7
Fix from $1,950 2006-02-24
Firefox MEDIUM 5.8
CVE-2006-0298

The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly r…

Patch available
Fix from $1,600 2006-02-02
Mozilla MEDIUM 5.0
CVE-2002-2314EPSS 9%

Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which caus…

Patch available
Fix from $1,600 2002-12-31
Mozilla MEDIUM 5.0
CVE-2002-2338

The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no …

Patch available
Fix from $1,600 2002-12-31