Vulnerability index

Browse CVEs

99 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.0 CVE-2008-2805 Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client compute… Firefox after 2.0.0.14 Fix from $1,6002008-07-07 HIGH 9.3 CVE-2007-4841 Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1… Firefox after 2.0.0.8 Fix from $1,9502007-09-12 MEDIUM 6.4 CVE-2007-0802 Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain nam… Firefox No fix yet Fix from $1,6002007-02-07 MEDIUM 5.0 CVE-2006-6971 Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP… Firefox No fix yet Fix from $1,6002007-02-07 MEDIUM 5.5 CVE-2006-0914 Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, whi… Bugzilla Patch available Fix from $1,6002006-02-28 HIGH 9.3 CVE-2006-0884EPSS 7% The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript securi… Thunderbird after 1.0.7 Fix from $1,9502006-02-24 MEDIUM 5.8 CVE-2006-0298 The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly r… Firefox Patch available Fix from $1,6002006-02-02 MEDIUM 5.0 CVE-2002-2314EPSS 9% Mozilla 1.0 allows remote attackers to steal cookies from other domains via a javascript: URL with a leading "//" and ending in a newline, which caus… Mozilla Patch available Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2338 The POP3 mail client in Mozilla 1.0 and earlier, and Netscape Communicator 4.7 and earlier, allows remote attackers to cause a denial of service (no … Mozilla Patch available Fix from $1,6002002-12-31