Vulnerability index

Browse CVEs

113 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Firefox MEDIUM 5.0
CVE-2010-0220

The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a deni…

Fix: after 3.5.6
Fix from $1,600 2010-01-07
Firefox HIGH 9.3
CVE-2009-3388

liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (app…

Fix: after 2.0
Fix from $1,950 2009-12-17
Firefox HIGH 9.3
CVE-2009-3980

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remot…

Fix: after 2.0
Fix from $1,950 2009-12-17
Firefox HIGH 10.0
CVE-2009-3371EPSS 7%

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possib…

Patch available
Fix from $1,950 2009-10-29
Firefox MEDIUM 5.0
CVE-2008-7244

Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop,…

Fix: after 3.0.1
Fix from $1,600 2009-09-18
Firefox MEDIUM 5.0
CVE-2009-2953

Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a lo…

Mitigation only
Fix from $1,600 2009-08-24
Firefox HIGH 9.3
CVE-2009-2663

libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of se…

Fix: after 3.5.1
Fix from $1,950 2009-08-04
Firefox MEDIUM 5.0
CVE-2009-2664

The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial …

Fix: after 3.5.1
Fix from $1,600 2009-08-04
Firefox HIGH 10.0
CVE-2009-2462EPSS 5%

The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and appli…

Patch available
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2464EPSS 13%

The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote att…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2465EPSS 5%

Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execut…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2469EPSS 6%

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, whi…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox MEDIUM 5.0
CVE-2009-1827

The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Ra…

No fix yet
Fix from $1,600 2009-05-29
Firefox MEDIUM 5.0
CVE-2009-1828EPSS 9%

Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN el…

No fix yet
Fix from $1,600 2009-05-29
Firefox HIGH 9.3
CVE-2009-1313EPSS 8%

The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,950 2009-04-30
Firefox MEDIUM 5.0
CVE-2009-1302

The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a d…

Fix: after 2.0.0.19
Fix from $1,600 2009-04-22
Firefox MEDIUM 5.0
CVE-2009-1304

The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause …

Fix: after 2.0.0.19
Fix from $1,600 2009-04-22
Firefox MEDIUM 5.0
CVE-2009-1305

The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a de…

Fix: after 2.0.0.19
Fix from $1,600 2009-04-22
Firefox HIGH 9.3
CVE-2009-1169EPSS 10%

The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a de…

Fix: after 3.0.7
Fix from $1,950 2009-03-27
Firefox HIGH 9.3
CVE-2009-1044EPSS 6%

Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree met…

Patch available
Fix from $1,950 2009-03-23
Firefox HIGH 10.0
CVE-2009-0771

The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of ser…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 10.0
CVE-2009-0773EPSS 6%

The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 10.0
CVE-2009-0775

Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execut…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 9.3
CVE-2009-0772

The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denia…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 9.3
CVE-2009-0774

The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denia…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox MEDIUM 5.0
CVE-2009-0821EPSS 5%

Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print fu…

Fix: after 2.0.0.20
Fix from $1,600 2009-03-05
Firefox HIGH 10.0
CVE-2009-0352

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attac…

Fix: after 2.0.0.19
Fix from $1,950 2009-02-04
Firefox HIGH 10.0
CVE-2009-0353

Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to ca…

Fix: after 2.0.0.19
Fix from $1,950 2009-02-04
Libxul MEDIUM 5.0
CVE-2008-5822

Memory leak in Libxul, as used in Mozilla Firefox 3.0.5 and other products, allows remote attackers to cause a denial of service (memory consumption …

No fix yet
Fix from $1,600 2009-01-02
Firefox HIGH 10.0
CVE-2008-5500

The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow…

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,950 2008-12-17