Vulnerability index

Browse CVEs

183 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Bugzilla HIGH 7.5
CVE-2009-0486

Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the sam…

Mitigation only
Fix from $1,950 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0482

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote at…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0483

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remot…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0484

Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delet…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0485

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote at…

Mitigation only
Fix from $1,600 2009-02-09
Firefox MEDIUM 6.8
CVE-2009-0253

Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to th…

No fix yet
Fix from $1,600 2009-01-22
Libxul MEDIUM 5.0
CVE-2008-5822

Memory leak in Libxul, as used in Mozilla Firefox 3.0.5 and other products, allows remote attackers to cause a denial of service (memory consumption …

No fix yet
Fix from $1,600 2009-01-02
Firefox MEDIUM 5.0
CVE-2008-5715EPSS 9%

Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long strin…

No fix yet
Fix from $1,600 2008-12-24
Firefox MEDIUM 5.0
CVE-2008-4324EPSS 9%

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer der…

No fix yet
Fix from $1,600 2008-09-29
Firefox HIGH 7.5
CVE-2008-3198

Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrat…

Mitigation only
Fix from $1,950 2008-07-17
Firefox HIGH 7.5
CVE-2008-2806

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary …

Mitigation only
Fix from $1,950 2008-07-07
Firefox HIGH 10.0
CVE-2008-2786

Buffer overflow in Firefox 3.0 and 2.0.x has unknown impact and attack vectors. NOTE: due to lack of details as of 20080619, it is not clear whether…

No fix yet
Fix from $1,950 2008-06-19
Firefox MEDIUM 5.0
CVE-2008-2014

Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in …

Mitigation only
Fix from $1,600 2008-04-30
Firefox HIGH 7.1
CVE-2007-5896

Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the …

Mitigation only
Fix from $1,950 2007-11-08
Firefox HIGH 9.3
CVE-2007-3845EPSS 6%

Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2007-08-08
Mozilla CRITICAL 9.8
CVE-2007-4039

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting atta…

Mitigation only
Fix from $2,300 2007-07-27
Firefox MEDIUM 6.8
CVE-2007-4041EPSS 20%

Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL b…

Mitigation only
Fix from $1,600 2007-07-27
Firefox MEDIUM 5.0
CVE-2007-3827

Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between…

Mitigation only
Fix from $1,600 2007-07-17
Firefox MEDIUM 6.8
CVE-2007-3656

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote …

No fix yet
Fix from $1,600 2007-07-10
Mozilla MEDIUM 6.4
CVE-2007-3144

Visual truncation vulnerability in Mozilla 1.7.12 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long h…

No fix yet
Fix from $1,600 2007-06-11
Firefox HIGH 7.1
CVE-2007-3072

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot enc…

No fix yet
Fix from $1,950 2007-06-06
Firefox HIGH 9.3
CVE-2007-2868

Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12…

Mitigation only
Fix from $1,950 2007-06-01
Firefox HIGH 7.1
CVE-2007-2671

Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A ele…

No fix yet
Fix from $1,950 2007-05-14
Firefox HIGH 10.0
CVE-2007-2176

Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. …

No fix yet
Fix from $1,950 2007-04-24
Firefox HIGH 7.8
CVE-2007-2162

(1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial of service (browser crash or system hang) via Java…

Mitigation only
Fix from $1,950 2007-04-22
Firefox MEDIUM 5.0
CVE-2007-1970

Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.writ…

Mitigation only
Fix from $1,600 2007-04-11
Firefox MEDIUM 5.0
CVE-2007-1762

Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote atta…

Mitigation only
Fix from $1,600 2007-03-30
Firefox HIGH 7.5
CVE-2007-1736

Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote a…

Mitigation only
Fix from $1,950 2007-03-28
Firefox MEDIUM 5.0
CVE-2007-1377EPSS 17%

AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspec…

No fix yet
Fix from $1,600 2007-03-10
Firefox MEDIUM 6.8
CVE-2007-1256

Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitr…

Mitigation only
Fix from $1,600 2007-03-03