Vulnerability index

Browse CVEs

57 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Firefox MEDIUM 6.8
CVE-2010-1215

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrap…

Mitigation only
Fix from $1,600 2010-07-30
Firefox HIGH 7.6
CVE-2010-0178

Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mou…

Fix: after 3.0.17
Fix from $1,950 2010-04-05
Firefox MEDIUM 5.1
CVE-2010-0179

Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, do…

Fix: after 3.0.17
Fix from $1,600 2010-04-05
Firefox HIGH 10.0
CVE-2010-1121EPSS 6%

Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote …

Mitigation only
Fix from $1,950 2010-03-25
Firefox HIGH 10.0
CVE-2009-1571EPSS 6%

Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonke…

Mitigation only
Fix from $1,950 2010-02-22
Firefox HIGH 7.6
CVE-2009-3986

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome…

Fix: after 3.0.15
Fix from $1,950 2009-12-17
Firefox HIGH 10.0
CVE-2009-3079

Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chro…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox HIGH 9.3
CVE-2009-3077

Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, whi…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox HIGH 10.0
CVE-2009-2665

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are ena…

Patch available
Fix from $1,950 2009-08-04
Firefox HIGH 9.3
CVE-2009-2477EPSS 43%

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to ex…

Patch available
Fix from $1,950 2009-07-15
Firefox HIGH 9.3
CVE-2009-1392EPSS 9%

The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a de…

Fix: after 2.0.0.19
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1832EPSS 9%

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory c…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1833EPSS 9%

The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a d…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1838

The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's ow…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1841

js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote a…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox MEDIUM 5.1
CVE-2008-5015

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page…

Fix: after 3.0.3
Fix from $1,600 2008-11-13
Firefox HIGH 7.5
CVE-2008-3198

Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrat…

Mitigation only
Fix from $1,950 2008-07-17
Firefox MEDIUM 6.8
CVE-2008-1233

Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to exec…

Fix: after 2.0.0.12
Fix from $1,600 2008-03-27
Firefox HIGH 9.3
CVE-2007-5045

Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows …

Fix: after 7.1.5
Fix from $1,950 2007-09-24
Firefox HIGH 9.3
CVE-2007-2868

Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12…

Mitigation only
Fix from $1,950 2007-06-01
Firefox MEDIUM 6.8
CVE-2007-0994

A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote …

Fix: 1.0.8 / 1.1.1+
Fix from $1,600 2007-03-06
Firefox HIGH 9.3
CVE-2006-6504EPSS 9%

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending a…

Fix: 1.0.7 / 1.5.0.9+
Fix from $1,950 2006-12-20
Firefox HIGH 9.3
CVE-2006-2779EPSS 7%

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1…

Patch available
Fix from $1,950 2006-06-02
Firefox HIGH 9.3
CVE-2006-2780EPSS 7%

Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute …

Fix: after 1.5.0.3
Fix from $1,950 2006-06-02
Thunderbird MEDIUM 5.1
CVE-2006-0236

GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an a…

Patch available
Fix from $1,600 2006-01-18
Firefox MEDIUM 5.0
CVE-2005-2703

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and poss…

Fix: after 1.7.11
Fix from $1,600 2005-09-23
Firefox HIGH 7.5
CVE-2005-1155EPSS 8%

The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="i…

Patch available
Fix from $1,950 2005-05-02