Vulnerability index

Browse CVEs

103 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Firefox MEDIUM 5.0
CVE-2011-2362

Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that d…

Fix: after 3.6.17
Fix from $1,600 2011-06-30
Firefox MEDIUM 5.0
CVE-2011-2370

Mozilla Firefox before 5.0 does not properly enforce the whitelist for the xpinstall functionality, which allows remote attackers to trigger an insta…

Fix: after 4.0.1
Fix from $1,600 2011-06-30
Bugzilla HIGH 7.5
CVE-2010-4568

Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not proper…

Mitigation only
Fix from $1,950 2011-01-28
Firefox MEDIUM 5.8
CVE-2010-3178

Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly ha…

Fix: after 3.5.13
Fix from $1,600 2010-10-21
Firefox MEDIUM 6.8
CVE-2010-2762

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x bef…

Mitigation only
Fix from $1,600 2010-09-09
Bugzilla MEDIUM 5.0
CVE-2010-2756

Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the …

Mitigation only
Fix from $1,600 2010-08-16
Bugzilla MEDIUM 5.0
CVE-2010-1204

Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive t…

Mitigation only
Fix from $1,600 2010-06-28
Firefox HIGH 7.6
CVE-2010-0168EPSS 12%

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.…

Patch available
Fix from $1,950 2010-03-25
Seamonkey HIGH 7.1
CVE-2009-3385

The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted r…

Fix: after 1.1.18
Fix from $1,950 2010-03-23
Firefox MEDIUM 5.0
CVE-2009-3988

Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties i…

Fix: after 3.0.17
Fix from $1,600 2010-02-22
Bugzilla MEDIUM 5.0
CVE-2009-3387

Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a differen…

Patch available
Fix from $1,600 2010-02-03
Firefox HIGH 7.5
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce i…

Patch available
Fix from $1,950 2009-10-29
Firefox HIGH 9.3
CVE-2009-1840

Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows …

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox MEDIUM 5.4
CVE-2009-1839EPSS 7%

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote…

Fix: after 3.0.10
Fix from $1,600 2009-06-12
Firefox HIGH 9.3
CVE-2009-1597

Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline …

No fix yet
Fix from $1,950 2009-05-11
Firefox MEDIUM 5.4
CVE-2009-0355

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab rest…

Fix: after 3.0.5
Fix from $1,600 2009-02-04
Firefox MEDIUM 5.0
CVE-2009-0357

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTT…

Fix: after 3.0.5
Fix from $1,600 2009-02-04
Firefox HIGH 7.5
CVE-2008-5504

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed previe…

Fix: after 2.0.0.18
Fix from $1,950 2008-12-17
Firefox MEDIUM 6.8
CVE-2008-5506

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to…

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox MEDIUM 6.8
CVE-2008-5512

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x …

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox MEDIUM 5.0
CVE-2008-5505

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to …

Fix: after 3.0.4
Fix from $1,600 2008-12-17
Firefox HIGH 7.5
CVE-2008-3835

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows rem…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-3836

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview a…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-4058EPSS 5%

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remo…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-4059

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chr…

Fix: after 2.0.0.17
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-4060

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create docum…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-2802

Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via a…

Fix: after 2.0.0.14
Fix from $1,950 2008-07-07
Firefox MEDIUM 6.8
CVE-2008-2803

The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does …

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Firefox MEDIUM 6.8
CVE-2008-2810

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assiste…

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Firefox HIGH 9.3
CVE-2007-5338

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Sc…

Fix: after 2.0.0.7
Fix from $1,950 2007-10-21