Vulnerability index

Browse CVEs

103 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Bugzilla HIGH 7.5
CVE-2007-5038

The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the c…

Patch available
Fix from $1,950 2007-09-24
Bugzilla MEDIUM 5.0
CVE-2007-4539

The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows r…

Patch available
Fix from $1,600 2007-08-27
Firefox MEDIUM 6.8
CVE-2007-3285

Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:…

Fix: after 2.0.0.4
Fix from $1,600 2007-06-20
Firefox HIGH 7.5
CVE-2007-0981EPSS 12%

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the sa…

Fix: after 1.5.0.9
Fix from $1,950 2007-02-16
Firefox MEDIUM 6.8
CVE-2006-6501

Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows …

Fix: 1.0.7 / 1.5.0.9+
Fix from $1,600 2006-12-20
Firefox HIGH 7.6
CVE-2006-4253EPSS 15%

Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute ar…

Mitigation only
Fix from $1,950 2006-08-21
Firefox MEDIUM 5.1
CVE-2006-2784

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user i…

Fix: after 1.5.0.3
Fix from $1,600 2006-06-02
Firefox HIGH 7.5
CVE-2006-2775

Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allo…

Fix: after 1.5.0.3
Fix from $1,950 2006-06-02
Firefox HIGH 9.3
CVE-2006-1726EPSS 7%

Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueTo…

Patch available
Fix from $1,950 2006-04-14
Firefox HIGH 9.3
CVE-2006-1735EPSS 9%

Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers …

Fix: after 1.7.12
Fix from $1,950 2006-04-14
Firefox MEDIUM 6.8
CVE-2006-1733EPSS 5%

Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protec…

Fix: after 1.7.12
Fix from $1,600 2006-04-14
Firefox HIGH 7.5
CVE-2005-1532EPSS 9%

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, wh…

Mitigation only
Fix from $1,950 2005-05-12
Firefox HIGH 7.5
CVE-2004-0867EPSS 17%

Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…

Mitigation only
Fix from $1,950 2004-12-23