Vulnerability index

Browse CVEs

57 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
MEDIUM 6.8 CVE-2010-1215 Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrap… Firefox Mitigation only Fix from $1,6002010-07-30 HIGH 7.6 CVE-2010-0178 Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mou… Firefox after 3.0.17 Fix from $1,9502010-04-05 MEDIUM 5.1 CVE-2010-0179 Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, do… Firefox after 3.0.17 Fix from $1,6002010-04-05 HIGH 10.0 CVE-2010-1121EPSS 6% Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote … Firefox Mitigation only Fix from $1,9502010-03-25 HIGH 10.0 CVE-2009-1571EPSS 6% Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonke… Firefox Mitigation only Fix from $1,9502010-02-22 HIGH 7.6 CVE-2009-3986 Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome… Firefox after 3.0.15 Fix from $1,9502009-12-17 HIGH 10.0 CVE-2009-3079 Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chro… Firefox after 3.0.13 Fix from $1,9502009-09-10 HIGH 9.3 CVE-2009-3077 Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, whi… Firefox after 3.0.13 Fix from $1,9502009-09-10 HIGH 10.0 CVE-2009-2665 The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are ena… Firefox Patch available Fix from $1,9502009-08-04 HIGH 9.3 CVE-2009-2477EPSS 43% js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to ex… Firefox Patch available Fix from $1,9502009-07-15 HIGH 9.3 CVE-2009-1392EPSS 9% The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a de… Firefox after 2.0.0.19 Fix from $1,9502009-06-12 HIGH 9.3 CVE-2009-1832EPSS 9% Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory c… Firefox after 3.0.10 Fix from $1,9502009-06-12 HIGH 9.3 CVE-2009-1833EPSS 9% The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a d… Firefox after 3.0.10 Fix from $1,9502009-06-12 HIGH 9.3 CVE-2009-1838 The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's ow… Firefox after 3.0.10 Fix from $1,9502009-06-12 HIGH 9.3 CVE-2009-1841 js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote a… Firefox after 3.0.10 Fix from $1,9502009-06-12 MEDIUM 5.1 CVE-2008-5015 Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page… Firefox after 3.0.3 Fix from $1,6002008-11-13 HIGH 7.5 CVE-2008-3198 Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrat… Firefox Mitigation only Fix from $1,9502008-07-17 MEDIUM 6.8 CVE-2008-1233 Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to exec… Firefox after 2.0.0.12 Fix from $1,6002008-03-27 HIGH 9.3 CVE-2007-5045 Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows … Firefox after 7.1.5 Fix from $1,9502007-09-24 HIGH 9.3 CVE-2007-2868 Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12… Firefox Mitigation only Fix from $1,9502007-06-01 MEDIUM 6.8 CVE-2007-0994 A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote … Firefox 1.0.8 / 1.1.1+ Fix from $1,6002007-03-06 HIGH 9.3 CVE-2006-6504EPSS 9% Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending a… Firefox 1.0.7 / 1.5.0.9+ Fix from $1,9502006-12-20 HIGH 9.3 CVE-2006-2779EPSS 7% Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1… Firefox Patch available Fix from $1,9502006-06-02 HIGH 9.3 CVE-2006-2780EPSS 7% Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute … Firefox after 1.5.0.3 Fix from $1,9502006-06-02 MEDIUM 5.1 CVE-2006-0236 GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an a… Thunderbird Patch available Fix from $1,6002006-01-18 MEDIUM 5.0 CVE-2005-2703 Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and poss… Firefox after 1.7.11 Fix from $1,6002005-09-23 HIGH 7.5 CVE-2005-1155EPSS 8% The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="i… Firefox Patch available Fix from $1,9502005-05-02