Vulnerability index

Browse CVEs

109 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Bugzilla MEDIUM 5.0
CVE-2010-3764

The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, whi…

Patch available
Fix from $1,600 2010-11-05
Bugzilla MEDIUM 5.0
CVE-2010-2758

Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whethe…

Mitigation only
Fix from $1,600 2010-08-16
Firefox MEDIUM 5.0
CVE-2010-2754

dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, an…

Fix: after 2.0.5
Fix from $1,600 2010-07-30
Firefox MEDIUM 5.8
CVE-2010-1125

The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to sen…

Fix: after 2.0.4
Fix from $1,600 2010-03-26
Seamonkey MEDIUM 5.0
CVE-2009-4629

Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or A…

Mitigation only
Fix from $1,600 2010-01-29
Firefox MEDIUM 5.0
CVE-2009-4630

Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML d…

Mitigation only
Fix from $1,600 2010-01-29
Firefox HIGH 7.8
CVE-2009-3987

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception me…

Fix: after 3.0.15
Fix from $1,950 2009-12-17
Bugzilla MEDIUM 5.0
CVE-2009-3386

Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) D…

Patch available
Fix from $1,600 2009-11-20
Firefox HIGH 7.1
CVE-2009-0776

nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-or…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox MEDIUM 6.0
CVE-2008-5507

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to …

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox MEDIUM 5.0
CVE-2008-5012

Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when proc…

Fix: after 2.0.0.17
Fix from $1,600 2008-11-13
Firefox MEDIUM 5.0
CVE-2008-4069

The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obt…

Fix: after 2.0.0.16
Fix from $1,600 2008-09-24
Firefox MEDIUM 5.0
CVE-2008-2807

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote att…

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Firefox HIGH 9.3
CVE-2008-0420

modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not pr…

Fix: after 2.0.0.11
Fix from $1,950 2008-02-12
Firefox MEDIUM 5.0
CVE-2008-0367

Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authen…

Fix: after 2.0.0.11
Fix from $1,600 2008-01-19
Firefox MEDIUM 6.8
CVE-2007-3656

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote …

No fix yet
Fix from $1,600 2007-07-10
Firefox MEDIUM 6.8
CVE-2007-1562EPSS 14%

The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to o…

Fix: 1.5.0.11 / 2.0.0.3+
Fix from $1,600 2007-03-21
Firefox MEDIUM 5.0
CVE-2007-1116

The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attac…

Patch available
Fix from $1,600 2007-02-26
Firefox MEDIUM 5.4
CVE-2007-0778

The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause …

Fix: 1.0.8 / 1.5.0.10+
Fix from $1,600 2007-02-26