Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.8
CVE-2009-0689EPSS 28%

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as …

Patch available
Fix from $1,600 2009-07-01
Seamonkey HIGH 9.3
CVE-2009-2210

Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly e…

Fix: after 2.0.0.21
Fix from $1,950 2009-06-25
Firefox HIGH 9.3
CVE-2009-2061

Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to ex…

Fix: after 3.0.9
Fix from $1,950 2009-06-15
Firefox MEDIUM 6.8
CVE-2009-2065

Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows m…

Fix: after 3.0.9
Fix from $1,600 2009-06-15
Firefox HIGH 9.3
CVE-2009-1392EPSS 9%

The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a de…

Fix: after 2.0.0.19
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1832EPSS 9%

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory c…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1833EPSS 9%

The JavaScript engine in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a d…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1838

The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's ow…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1840

Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows …

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 9.3
CVE-2009-1841

js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote a…

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Firefox HIGH 7.5
CVE-2009-1837

Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 mig…

Fix: 3.0.11+
Fix from $1,950 2009-06-12
Firefox MEDIUM 6.8
CVE-2009-1836

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a docume…

Fix: after 3.0.10
Fix from $1,600 2009-06-12
Firefox MEDIUM 5.4
CVE-2009-1839EPSS 7%

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote…

Fix: after 3.0.10
Fix from $1,600 2009-06-12
Firefox MEDIUM 5.0
CVE-2009-1827

The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Ra…

No fix yet
Fix from $1,600 2009-05-29
Firefox MEDIUM 5.0
CVE-2009-1828EPSS 9%

Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN el…

No fix yet
Fix from $1,600 2009-05-29
Firefox HIGH 9.3
CVE-2009-1597

Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline …

No fix yet
Fix from $1,950 2009-05-11
Firefox HIGH 9.3
CVE-2009-1313EPSS 8%

The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of …

Mitigation only
Fix from $1,950 2009-04-30
Firefox MEDIUM 6.8
CVE-2009-1307

The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, w…

Fix: after 3.0.8
Fix from $1,600 2009-04-22
Firefox MEDIUM 5.0
CVE-2009-1302

The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a d…

Fix: after 2.0.0.19
Fix from $1,600 2009-04-22
Firefox MEDIUM 5.0
CVE-2009-1303

The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denia…

Fix: after 3.0.8
Fix from $1,600 2009-04-22
Firefox MEDIUM 5.0
CVE-2009-1304

The JavaScript engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause …

Fix: after 2.0.0.19
Fix from $1,600 2009-04-22
Firefox MEDIUM 5.0
CVE-2009-1305

The JavaScript engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a de…

Fix: after 2.0.0.19
Fix from $1,600 2009-04-22
Bugzilla MEDIUM 6.8
CVE-2009-1213

Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 3.2 before 3.2.3, 3.3 before 3.3.4, and earlier versions allows remote …

Patch available
Fix from $1,600 2009-04-01
Firefox HIGH 9.3
CVE-2009-1169EPSS 10%

The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a de…

Fix: after 3.0.7
Fix from $1,950 2009-03-27
Firefox HIGH 9.3
CVE-2009-0723EPSS 5%

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependen…

Fix: 2.9.2+
Fix from $1,950 2009-03-23
Firefox HIGH 9.3
CVE-2009-0733EPSS 6%

Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta…

Fix: 2.9.2+
Fix from $1,950 2009-03-23
Firefox HIGH 9.3
CVE-2009-1044EPSS 6%

Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree met…

Patch available
Fix from $1,950 2009-03-23
Firefox HIGH 10.0
CVE-2009-0771

The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of ser…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 10.0
CVE-2009-0773EPSS 6%

The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 10.0
CVE-2009-0775

Double free vulnerability in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to execut…

Fix: after 3.0.6
Fix from $1,950 2009-03-05