Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 9.3
CVE-2010-0175EPSS 7%

Use-after-free vulnerability in the nsTreeSelection implementation in Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.9, Thunderbird before 3.0.4,…

Fix: after 3.0.17
Fix from $1,950 2010-04-05
Firefox HIGH 9.3
CVE-2010-0176EPSS 5%

Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manag…

Fix: after 3.5.7
Fix from $1,950 2010-04-05
Firefox HIGH 9.3
CVE-2010-0177EPSS 7%

Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, frees the contents of the window.navigator.plu…

Fix: after 3.0.17
Fix from $1,950 2010-04-05
Firefox HIGH 7.6
CVE-2010-0178

Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mou…

Fix: after 3.0.17
Fix from $1,950 2010-04-05
Firefox MEDIUM 5.1
CVE-2010-0179

Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, do…

Fix: after 3.0.17
Fix from $1,600 2010-04-05
Firefox MEDIUM 5.8
CVE-2010-1125

The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to sen…

Fix: after 2.0.4
Fix from $1,600 2010-03-26
Firefox HIGH 10.0
CVE-2010-1122

Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and applicat…

Mitigation only
Fix from $1,950 2010-03-25
Firefox HIGH 10.0
CVE-2010-1121EPSS 6%

Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote …

Mitigation only
Fix from $1,950 2010-03-25
Firefox HIGH 9.3
CVE-2010-0164EPSS 6%

Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.…

No fix yet
Fix from $1,950 2010-03-25
Firefox HIGH 9.3
CVE-2010-0165

The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attacke…

Mitigation only
Fix from $1,950 2010-03-25
Firefox HIGH 9.3
CVE-2010-0167EPSS 11%

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before…

Fix: after 3.0.1
Fix from $1,950 2010-03-25
Firefox HIGH 7.6
CVE-2010-0168EPSS 12%

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.…

Patch available
Fix from $1,950 2010-03-25
Firefox MEDIUM 5.1
CVE-2010-0166EPSS 7%

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when …

Mitigation only
Fix from $1,600 2010-03-25
Firefox MEDIUM 5.0
CVE-2010-0169

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x bef…

Fix: after 3.0.1
Fix from $1,600 2010-03-25
Seamonkey HIGH 7.1
CVE-2009-3385

The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted r…

Fix: after 1.1.18
Fix from $1,950 2010-03-23
Firefox HIGH 9.3
CVE-2010-1028EPSS 9%

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.…

Mitigation only
Fix from $1,950 2010-03-19
Firefox HIGH 10.0
CVE-2010-0159

The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote …

Fix: 2.0.3 / 3.0.2+
Fix from $1,950 2010-02-22
Firefox HIGH 10.0
CVE-2010-0160EPSS 6%

The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle arra…

Fix: after 3.0.17
Fix from $1,950 2010-02-22
Firefox HIGH 10.0
CVE-2009-1571EPSS 6%

Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonke…

Mitigation only
Fix from $1,950 2010-02-22
Firefox MEDIUM 5.0
CVE-2009-3988

Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties i…

Fix: after 3.0.17
Fix from $1,600 2010-02-22
Bugzilla MEDIUM 5.0
CVE-2009-3387

Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a differen…

Patch available
Fix from $1,600 2010-02-03
Seamonkey MEDIUM 5.0
CVE-2009-4629

Mozilla Necko, as used in Thunderbird 3.0.1, SeaMonkey, and other applications, performs DNS prefetching even when the app type is APP_TYPE_MAIL or A…

Mitigation only
Fix from $1,600 2010-01-29
Firefox MEDIUM 5.0
CVE-2009-4630

Mozilla Necko, as used in Firefox, SeaMonkey, and other applications, performs DNS prefetching of domain names contained in links within local HTML d…

Mitigation only
Fix from $1,600 2010-01-29
Firefox MEDIUM 5.0
CVE-2010-0220

The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a deni…

Fix: after 3.5.6
Fix from $1,600 2010-01-07
Firefox HIGH 9.3
CVE-2009-3388

liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (app…

Fix: after 2.0
Fix from $1,950 2009-12-17
Firefox HIGH 9.3
CVE-2009-3389

Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote at…

Fix: after 2.0
Fix from $1,950 2009-12-17
Firefox HIGH 9.3
CVE-2009-3979

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thund…

Fix: after 3.0.15
Fix from $1,950 2009-12-17
Firefox HIGH 9.3
CVE-2009-3980

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remot…

Fix: after 2.0
Fix from $1,950 2009-12-17
Firefox HIGH 9.3
CVE-2009-3981

Unspecified vulnerability in the browser engine in Mozilla Firefox before 3.0.16, SeaMonkey before 2.0.1, and Thunderbird allows remote attackers to …

Fix: after 3.0.15
Fix from $1,950 2009-12-17
Firefox HIGH 9.3
CVE-2009-3982

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow re…

Fix: after 2.0
Fix from $1,950 2009-12-17