Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 7.8
CVE-2009-3987

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception me…

Fix: after 3.0.15
Fix from $1,950 2009-12-17
Firefox HIGH 7.6
CVE-2009-3986

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome…

Fix: after 3.0.15
Fix from $1,950 2009-12-17
Firefox MEDIUM 6.8
CVE-2009-3983

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to send authenticated requests to arbitrary…

Fix: after 3.0.15
Fix from $1,600 2009-12-17
Firefox MEDIUM 6.8
CVE-2009-3984

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to spoof an SSL indicator for an http URL o…

Fix: after 3.0.15
Fix from $1,600 2009-12-17
Firefox MEDIUM 6.8
CVE-2009-3985

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invali…

Fix: after 3.0.15
Fix from $1,600 2009-12-17
Firefox MEDIUM 5.8
CVE-2009-4129

Race condition in Mozilla Firefox allows remote attackers to produce a JavaScript message with a spoofed domain association by writing the message in…

Mitigation only
Fix from $1,600 2009-12-14
Firefox MEDIUM 5.8
CVE-2009-4130

Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the o…

Mitigation only
Fix from $1,600 2009-12-14
Firefox HIGH 9.3
CVE-2009-4102

Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary c…

Fix: after 1.4.3
Fix from $1,950 2009-11-29
Bugzilla MEDIUM 5.0
CVE-2009-3386

Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1 allows remote attackers to discover the alias of a private bug by reading the (1) D…

Patch available
Fix from $1,600 2009-11-20
Firefox HIGH 10.0
CVE-2009-3377

Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to ca…

Patch available
Fix from $1,950 2009-10-29
Firefox HIGH 10.0
CVE-2009-3379EPSS 5%

Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service…

Patch available
Fix from $1,950 2009-10-29
Firefox HIGH 10.0
CVE-2009-3380EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to ca…

Patch available
Fix from $1,950 2009-10-29
Firefox HIGH 10.0
CVE-2009-3381

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service …

Patch available
Fix from $1,950 2009-10-29
Firefox HIGH 10.0
CVE-2009-3382EPSS 11%

layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, whic…

Patch available
Fix from $1,950 2009-10-29
Firefox HIGH 10.0
CVE-2009-3383

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2009-10-29
Firefox HIGH 9.3
CVE-2009-3378

The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x befor…

Patch available
Fix from $1,950 2009-10-29
Firefox HIGH 10.0
CVE-2009-3371EPSS 7%

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possib…

Patch available
Fix from $1,950 2009-10-29
Firefox HIGH 10.0
CVE-2009-3373EPSS 16%

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote a…

Fix: after 1.5.0.10
Fix from $1,950 2009-10-29
Firefox HIGH 9.3
CVE-2009-3372

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regul…

Fix: after 1.5.0.10
Fix from $1,950 2009-10-29
Firefox HIGH 9.3
CVE-2009-3376

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E)…

Fix: after 1.5.0.10
Fix from $1,950 2009-10-29
Firefox HIGH 7.5
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce i…

Patch available
Fix from $1,950 2009-10-29
Firefox MEDIUM 5.0
CVE-2009-3370

Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverag…

Mitigation only
Fix from $1,600 2009-10-29
Firefox MEDIUM 5.0
CVE-2008-7244

Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop,…

Fix: after 3.0.1
Fix from $1,600 2009-09-18
Bugzilla HIGH 7.5
CVE-2009-3125

SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitr…

Patch available
Fix from $1,950 2009-09-15
Bugzilla HIGH 7.5
CVE-2009-3165

SQL injection vulnerability in the Bug.create WebService function in Bugzilla 2.23.4 through 3.0.8, 3.1.1 through 3.2.4, and 3.3.1 through 3.4.1 allo…

Patch available
Fix from $1,950 2009-09-15
Bugzilla MEDIUM 5.0
CVE-2009-3166

token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password re…

Patch available
Fix from $1,600 2009-09-15
Firefox HIGH 10.0
CVE-2009-3069

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory co…

Mitigation only
Fix from $1,950 2009-09-10
Firefox HIGH 10.0
CVE-2009-3070EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memo…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox HIGH 10.0
CVE-2009-3071EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause …

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox HIGH 10.0
CVE-2009-3072EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and …

Fix: after 3.0.13
Fix from $1,950 2009-09-10