Vulnerability index

Browse CVEs

183 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 5.0
CVE-2005-4809EPSS 6%

Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via …

No fix yet
Fix from $1,600 2005-12-31
Mozilla HIGH 7.8
CVE-2005-3896

Mozilla allows remote attackers to cause a denial of service (CPU consumption) via a Javascript BODY onload event that calls the window function.

No fix yet
Fix from $1,950 2005-11-29
Firefox HIGH 7.5
CVE-2005-2871EPSS 21%

Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote atta…

No fix yet
Fix from $1,950 2005-09-09
Firefox MEDIUM 5.0
CVE-2005-2429

Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbi…

Mitigation only
Fix from $1,600 2005-08-03
Firefox MEDIUM 5.0
CVE-2005-2395

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might …

No fix yet
Fix from $1,600 2005-07-27
Firefox HIGH 7.5
CVE-2005-2267

Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash …

Mitigation only
Fix from $1,950 2005-07-13
Firefox MEDIUM 5.1
CVE-2005-2262EPSS 7%

Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper"…

Mitigation only
Fix from $1,600 2005-07-13
Firefox MEDIUM 5.0
CVE-2005-2114

Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote att…

No fix yet
Fix from $1,600 2005-07-05
Firefox MEDIUM 5.0
CVE-2005-1575

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via th…

Mitigation only
Fix from $1,600 2005-05-14
Firefox HIGH 7.5
CVE-2005-1532EPSS 9%

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, wh…

Mitigation only
Fix from $1,950 2005-05-12
Thunderbird MEDIUM 5.0
CVE-2005-0148

Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer …

No fix yet
Fix from $1,600 2005-05-02
Mozilla MEDIUM 5.0
CVE-2005-0215

Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a lar…

Mitigation only
Fix from $1,600 2005-05-02
Firefox HIGH 7.5
CVE-2005-0592

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a…

Mitigation only
Fix from $1,950 2005-03-25
Firefox HIGH 10.0
CVE-2004-0904EPSS 8%

Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow r…

Mitigation only
Fix from $1,950 2004-12-31
Mozilla MEDIUM 5.1
CVE-2004-0909

Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performin…

No fix yet
Fix from $1,600 2004-12-31
Firefox MEDIUM 5.0
CVE-2004-1200

Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript…

No fix yet
Fix from $1,600 2004-12-31
Firefox HIGH 7.5
CVE-2004-0867EPSS 17%

Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…

Mitigation only
Fix from $1,950 2004-12-23
Bugzilla MEDIUM 5.0
CVE-2004-1633

process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenti…

Mitigation only
Fix from $1,600 2004-10-25
Mozilla MEDIUM 5.0
CVE-2004-1614

Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual ele…

No fix yet
Fix from $1,600 2004-10-18
Mozilla MEDIUM 5.0
CVE-2004-0871

Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same dom…

Mitigation only
Fix from $1,600 2004-09-16
Mozilla HIGH 10.0
CVE-2004-0722EPSS 13%

Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allo…

Mitigation only
Fix from $1,950 2004-08-18
Firefox HIGH 7.5
CVE-2004-0779

The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only …

Mitigation only
Fix from $1,950 2004-08-18
Mozilla HIGH 7.5
CVE-2003-0594

Mozilla allows remote attackers to bypass intended cookie access restrictions on a web application via "%2e%2e" (encoded dot dot) directory traversal…

No fix yet
Fix from $1,950 2004-04-15
Mozilla MEDIUM 6.8
CVE-2004-0191

Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page…

No fix yet
Fix from $1,600 2004-03-15
Firefox MEDIUM 5.0
CVE-2003-1492

Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with…

No fix yet
Fix from $1,600 2003-12-31
Mozilla HIGH 7.5
CVE-2003-0298

The IMAP Client for Mozilla 1.3 and 1.4a allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via ce…

Mitigation only
Fix from $1,950 2003-06-16
Mozilla HIGH 7.5
CVE-2002-1308

Heap-based buffer overflow in Netscape and Mozilla allows remote attackers to execute arbitrary code via a jar: URL that references a malformed .jar …

Mitigation only
Fix from $1,950 2002-11-29
Bugzilla HIGH 7.5
CVE-2002-1197

bugzilla_email_append.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell meta…

Mitigation only
Fix from $1,950 2002-10-28
Bugzilla HIGH 7.5
CVE-2002-1198

Bugzilla 2.16.x before 2.16.1 does not properly filter apostrophes from an email address during account creation, which allows remote attackers to ex…

Mitigation only
Fix from $1,950 2002-10-28
Bugzilla HIGH 7.5
CVE-2002-0811

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, may allow remote attackers to cause a denial of service or execute certain queries via a SQL in…

Mitigation only
Fix from $1,950 2002-08-12