Vulnerability index

Browse CVEs

183 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2009-0486 Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the sam… Bugzilla Mitigation only Fix from $1,9502009-02-09 MEDIUM 5.8 CVE-2009-0482 Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote at… Bugzilla Mitigation only Fix from $1,6002009-02-09 MEDIUM 5.8 CVE-2009-0483 Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remot… Bugzilla Mitigation only Fix from $1,6002009-02-09 MEDIUM 5.8 CVE-2009-0484 Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delet… Bugzilla Mitigation only Fix from $1,6002009-02-09 MEDIUM 5.8 CVE-2009-0485 Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote at… Bugzilla Mitigation only Fix from $1,6002009-02-09 MEDIUM 6.8 CVE-2009-0253 Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to th… Firefox No fix yet Fix from $1,6002009-01-22 MEDIUM 5.0 CVE-2008-5822 Memory leak in Libxul, as used in Mozilla Firefox 3.0.5 and other products, allows remote attackers to cause a denial of service (memory consumption … Libxul No fix yet Fix from $1,6002009-01-02 MEDIUM 5.0 CVE-2008-5715EPSS 9% Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long strin… Firefox No fix yet Fix from $1,6002008-12-24 MEDIUM 5.0 CVE-2008-4324EPSS 9% The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer der… Firefox No fix yet Fix from $1,6002008-09-29 HIGH 7.5 CVE-2008-3198 Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrat… Firefox Mitigation only Fix from $1,9502008-07-17 HIGH 7.5 CVE-2008-2806 Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary … Firefox Mitigation only Fix from $1,9502008-07-07 HIGH 10.0 CVE-2008-2786 Buffer overflow in Firefox 3.0 and 2.0.x has unknown impact and attack vectors. NOTE: due to lack of details as of 20080619, it is not clear whether… Firefox No fix yet Fix from $1,9502008-06-19 MEDIUM 5.0 CVE-2008-2014 Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in … Firefox Mitigation only Fix from $1,6002008-04-30 HIGH 7.1 CVE-2007-5896 Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the … Firefox Mitigation only Fix from $1,9502007-11-08 HIGH 9.3 CVE-2007-3845EPSS 6% Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbi… Firefox Mitigation only Fix from $1,9502007-08-08 CRITICAL 9.8 CVE-2007-4039 Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting atta… Mozilla Mitigation only Fix from $2,3002007-07-27 MEDIUM 6.8 CVE-2007-4041EPSS 20% Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL b… Firefox Mitigation only Fix from $1,6002007-07-27 MEDIUM 5.0 CVE-2007-3827 Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between… Firefox Mitigation only Fix from $1,6002007-07-17 MEDIUM 6.8 CVE-2007-3656 Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote … Firefox No fix yet Fix from $1,6002007-07-10 MEDIUM 6.4 CVE-2007-3144 Visual truncation vulnerability in Mozilla 1.7.12 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long h… Mozilla No fix yet Fix from $1,6002007-06-11 HIGH 7.1 CVE-2007-3072 Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot enc… Firefox No fix yet Fix from $1,9502007-06-06 HIGH 9.3 CVE-2007-2868 Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12… Firefox Mitigation only Fix from $1,9502007-06-01 HIGH 7.1 CVE-2007-2671 Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A ele… Firefox No fix yet Fix from $1,9502007-05-14 HIGH 10.0 CVE-2007-2176 Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. … Firefox No fix yet Fix from $1,9502007-04-24 HIGH 7.8 CVE-2007-2162 (1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial of service (browser crash or system hang) via Java… Firefox Mitigation only Fix from $1,9502007-04-22 MEDIUM 5.0 CVE-2007-1970 Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.writ… Firefox Mitigation only Fix from $1,6002007-04-11 MEDIUM 5.0 CVE-2007-1762 Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote atta… Firefox Mitigation only Fix from $1,6002007-03-30 HIGH 7.5 CVE-2007-1736 Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote a… Firefox Mitigation only Fix from $1,9502007-03-28 MEDIUM 5.0 CVE-2007-1377EPSS 17% AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspec… Firefox No fix yet Fix from $1,6002007-03-10 MEDIUM 6.8 CVE-2007-1256 Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitr… Firefox Mitigation only Fix from $1,6002007-03-03