Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 9.3
CVE-2009-0772

The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denia…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 9.3
CVE-2009-0774

The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denia…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox HIGH 7.1
CVE-2009-0776

nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-or…

Fix: after 3.0.6
Fix from $1,950 2009-03-05
Firefox MEDIUM 5.8
CVE-2009-0777

Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 decode invisible characters when they are displayed in the loc…

Fix: after 3.0.6
Fix from $1,600 2009-03-05
Firefox MEDIUM 5.0
CVE-2009-0821EPSS 5%

Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print fu…

Fix: after 2.0.0.20
Fix from $1,600 2009-03-05
Firefox MEDIUM 5.8
CVE-2009-0652

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonk…

Fix: after 3.0.6
Fix from $1,600 2009-02-20
Bugzilla HIGH 7.5
CVE-2009-0486

Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the sam…

Mitigation only
Fix from $1,950 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0482

Cross-site request forgery (CSRF) vulnerability in Bugzilla before 3.2 before 3.2.1, 3.3 before 3.3.2, and other versions before 3.2 allows remote at…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0483

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remot…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0484

Cross-site request forgery (CSRF) vulnerability in Bugzilla 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delet…

Mitigation only
Fix from $1,600 2009-02-09
Bugzilla MEDIUM 5.8
CVE-2009-0485

Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote at…

Mitigation only
Fix from $1,600 2009-02-09
Firefox HIGH 10.0
CVE-2009-0352

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attac…

Fix: after 2.0.0.19
Fix from $1,950 2009-02-04
Firefox HIGH 10.0
CVE-2009-0353

Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to ca…

Fix: after 2.0.0.19
Fix from $1,950 2009-02-04
Firefox MEDIUM 5.4
CVE-2009-0355

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab rest…

Fix: after 3.0.5
Fix from $1,600 2009-02-04
Firefox MEDIUM 5.1
CVE-2009-0356

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows us…

Fix: after 3.0.5
Fix from $1,600 2009-02-04
Firefox MEDIUM 5.0
CVE-2009-0357

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTT…

Fix: after 3.0.5
Fix from $1,600 2009-02-04
Firefox MEDIUM 6.8
CVE-2009-0253

Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to th…

No fix yet
Fix from $1,600 2009-01-22
Libxul MEDIUM 5.0
CVE-2008-5822

Memory leak in Libxul, as used in Mozilla Firefox 3.0.5 and other products, allows remote attackers to cause a denial of service (memory consumption …

No fix yet
Fix from $1,600 2009-01-02
Firefox MEDIUM 5.0
CVE-2008-5715EPSS 9%

Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long strin…

No fix yet
Fix from $1,600 2008-12-24
Firefox HIGH 10.0
CVE-2008-5500

The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow…

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,950 2008-12-17
Firefox HIGH 7.5
CVE-2008-5504

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed previe…

Fix: after 2.0.0.18
Fix from $1,950 2008-12-17
Firefox MEDIUM 6.8
CVE-2008-5506

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to…

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox MEDIUM 6.8
CVE-2008-5512

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x …

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox MEDIUM 6.0
CVE-2008-5507

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to …

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox MEDIUM 5.0
CVE-2008-5501

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to ca…

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox MEDIUM 5.0
CVE-2008-5502

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to ca…

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox MEDIUM 5.0
CVE-2008-5505

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to …

Fix: after 3.0.4
Fix from $1,600 2008-12-17
Firefox MEDIUM 5.0
CVE-2008-5510

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores …

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox HIGH 10.0
CVE-2008-5014EPSS 6%

jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows …

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 10.0
CVE-2008-5017

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x bef…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13