Vulnerability index

Browse CVEs

183 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.4
CVE-2007-0802

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain nam…

No fix yet
Fix from $1,600 2007-02-07
Firefox MEDIUM 5.0
CVE-2006-6971

Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP…

No fix yet
Fix from $1,600 2007-02-07
Bugzilla HIGH 7.5
CVE-2007-0792

The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file …

Mitigation only
Fix from $1,950 2007-02-06
Durian Web Application Server HIGH 10.0
CVE-2006-6853EPSS 8%

Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a cr…

No fix yet
Fix from $1,950 2006-12-31
Firefox HIGH 7.1
CVE-2006-6502

Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9,…

Mitigation only
Fix from $1,950 2006-12-20
Firefox MEDIUM 6.8
CVE-2006-6498

Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.…

Mitigation only
Fix from $1,600 2006-12-20
Firefox MEDIUM 6.4
CVE-2006-6585

The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extensi…

Mitigation only
Fix from $1,600 2006-12-15
Firefox HIGH 7.8
CVE-2006-5783

Firefox 1.5.0.7 on Kubuntu Linux allows remote attackers to cause a denial of service (crash) via a long URL in an A tag. NOTE: this issue has been …

No fix yet
Fix from $1,950 2006-11-07
Firefox MEDIUM 5.0
CVE-2006-5633EPSS 7%

Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRang…

No fix yet
Fix from $1,600 2006-10-31
Firefox HIGH 8.1
CVE-2006-5160

Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and or…

No fix yet
Fix from $1,950 2006-10-05
Firefox HIGH 7.5
CVE-2006-5159EPSS 6%

Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving JavaScript. NOTE:…

No fix yet
Fix from $1,950 2006-10-05
Firefox HIGH 7.5
CVE-2006-4561

Mozilla Firefox 1.5.0.6 allows remote attackers to execute arbitrary JavaScript in the context of the browser's session with an arbitrary intranet we…

No fix yet
Fix from $1,950 2006-09-06
Firefox HIGH 7.6
CVE-2006-4253EPSS 15%

Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute ar…

Mitigation only
Fix from $1,950 2006-08-21
Firefox MEDIUM 6.4
CVE-2006-3352

Cross-domain vulnerability in Mozilla Firefox allows remote attackers to access restricted information from other domains via an object tag with a da…

Mitigation only
Fix from $1,600 2006-07-06
Firefox HIGH 9.3
CVE-2006-2787

EvalInSandbox in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to gain privileges via javascript that calls the valueOf meth…

Mitigation only
Fix from $1,950 2006-06-02
Firefox MEDIUM 5.0
CVE-2006-2723

Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) via a web page that contains a large number of ne…

No fix yet
Fix from $1,600 2006-06-01
Firefox MEDIUM 5.0
CVE-2006-2057

Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers to modify command line arguments to an invoked mail c…

Mitigation only
Fix from $1,600 2006-04-26
Camino MEDIUM 5.0
CVE-2006-1901

Mozilla Camino 1.0 and earlier allow remote attackers to cause a denial of service (null dereference and application crash or hang) via HTML with cer…

Mitigation only
Fix from $1,600 2006-04-20
Firefox HIGH 10.0
CVE-2006-1790EPSS 5%

A regression fix in Mozilla Firefox 1.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the In…

Mitigation only
Fix from $1,950 2006-04-14
Firefox HIGH 9.3
CVE-2006-1737

Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allo…

Mitigation only
Fix from $1,950 2006-04-14
Firefox MEDIUM 5.0
CVE-2006-1738

Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before…

Mitigation only
Fix from $1,600 2006-04-14
Firefox HIGH 9.3
CVE-2006-0748EPSS 8%

Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote atta…

Mitigation only
Fix from $1,950 2006-04-14
Firefox HIGH 7.5
CVE-2006-1723

Unspecified vulnerability in Firefox and Thunderbird before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to cause a denial of service…

Mitigation only
Fix from $1,950 2006-04-14
Firefox MEDIUM 5.0
CVE-2006-1650

Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockw…

Mitigation only
Fix from $1,600 2006-04-06
Firefox HIGH 7.8
CVE-2006-1273

Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action h…

Mitigation only
Fix from $1,950 2006-03-19
Bugzilla HIGH 7.5
CVE-2006-0915

Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which al…

Mitigation only
Fix from $1,950 2006-02-28
Firefox MEDIUM 6.4
CVE-2006-0299

The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the interna…

Mitigation only
Fix from $1,600 2006-02-02
Firefox MEDIUM 5.1
CVE-2006-0297

Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote atta…

Mitigation only
Fix from $1,600 2006-02-02
Firefox MEDIUM 5.0
CVE-2006-0296

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remo…

Mitigation only
Fix from $1,600 2006-02-02
Firefox MEDIUM 6.4
CVE-2005-4685

Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote …

Mitigation only
Fix from $1,600 2005-12-31