Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 10.0
CVE-2009-3073

Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory…

Mitigation only
Fix from $1,950 2009-09-10
Firefox HIGH 10.0
CVE-2009-3074EPSS 5%

Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corr…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox HIGH 10.0
CVE-2009-3075EPSS 5%

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, a…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox HIGH 10.0
CVE-2009-3079

Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chro…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox HIGH 9.3
CVE-2009-3076EPSS 7%

Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operat…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox HIGH 9.3
CVE-2009-3077

Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, whi…

Fix: after 3.0.13
Fix from $1,950 2009-09-10
Firefox MEDIUM 5.0
CVE-2009-3078

Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and sp…

Fix: after 3.0.13
Fix from $1,600 2009-09-10
Firefox MEDIUM 5.0
CVE-2009-2975

Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement s…

No fix yet
Fix from $1,600 2009-08-27
Firefox MEDIUM 5.0
CVE-2009-2953

Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a lo…

Mitigation only
Fix from $1,600 2009-08-24
Firefox HIGH 10.0
CVE-2009-2662

The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application cras…

Fix: after 3.0.12
Fix from $1,950 2009-08-04
Firefox HIGH 10.0
CVE-2009-2665

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are ena…

Patch available
Fix from $1,950 2009-08-04
Firefox HIGH 9.3
CVE-2009-2663

libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of se…

Fix: after 3.5.1
Fix from $1,950 2009-08-04
Firefox MEDIUM 5.0
CVE-2009-2470

Mozilla Firefox before 3.0.12, and 3.5.x before 3.5.2, allows remote SOCKS5 proxy servers to cause a denial of service (data stream corruption) via a…

Fix: after 3.5.1
Fix from $1,600 2009-08-04
Firefox MEDIUM 5.0
CVE-2009-2664

The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial …

Fix: after 3.5.1
Fix from $1,600 2009-08-04
Network Security Services HIGH 9.3
CVE-2009-2404

Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, …

Patch available
Fix from $1,950 2009-08-03
Firefox MEDIUM 5.8
CVE-2009-2654

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a…

Fix: after 3.5.1
Fix from $1,600 2009-08-03
Firefox MEDIUM 5.9
CVE-2009-2408EPSS 6%

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properl…

Fix: 1.1.18 / 2.0.0.23+
Fix from $1,600 2009-07-30
Firefox HIGH 10.0
CVE-2009-2462EPSS 5%

The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and appli…

Patch available
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2463EPSS 6%

Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.…

Patch available
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2464EPSS 13%

The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote att…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2465EPSS 5%

Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execut…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2466EPSS 7%

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and ap…

Fix: 3.0.12+
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2467EPSS 5%

Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbit…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2468EPSS 6%

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2469EPSS 6%

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, whi…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox HIGH 10.0
CVE-2009-2471

The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitra…

Fix: after 3.0.11
Fix from $1,950 2009-07-22
Firefox MEDIUM 5.0
CVE-2009-2535EPSS 9%

Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denial of service (memory consumpt…

Fix: after 2.0.0.18
Fix from $1,600 2009-07-20
Firefox HIGH 7.8
CVE-2009-2479EPSS 12%

Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via …

No fix yet
Fix from $1,950 2009-07-16
Firefox MEDIUM 5.0
CVE-2009-2478EPSS 8%

Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, re…

No fix yet
Fix from $1,600 2009-07-16
Firefox HIGH 9.3
CVE-2009-2477EPSS 43%

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to ex…

Patch available
Fix from $1,950 2009-07-15