Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 10.0
CVE-2008-5018

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 10.0
CVE-2008-5052

The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x…

Fix: 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 9.3
CVE-2008-0017EPSS 8%

The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 d…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 9.3
CVE-2008-5013

Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properl…

Fix: after 2.0.0.17
Fix from $1,950 2008-11-13
Firefox HIGH 9.3
CVE-2008-5021

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remo…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 7.5
CVE-2008-5022

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaM…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 7.5
CVE-2008-5023

Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox HIGH 7.5
CVE-2008-5024

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escap…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Firefox MEDIUM 5.1
CVE-2008-5015

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page…

Fix: after 3.0.3
Fix from $1,600 2008-11-13
Firefox MEDIUM 5.0
CVE-2008-5012

Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when proc…

Fix: after 2.0.0.17
Fix from $1,600 2008-11-13
Firefox MEDIUM 5.0
CVE-2008-5016

The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to ca…

Fix: after 3.0.3
Fix from $1,600 2008-11-13
Bugzilla HIGH 7.1
CVE-2008-4437EPSS 6%

Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attac…

Patch available
Fix from $1,950 2008-10-03
Firefox MEDIUM 5.0
CVE-2008-4324EPSS 9%

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer der…

No fix yet
Fix from $1,600 2008-09-29
Seamonkey HIGH 10.0
CVE-2008-4070EPSS 7%

Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (a…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-27
Firefox HIGH 10.0
CVE-2008-0016EPSS 44%

Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers …

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Firefox HIGH 10.0
CVE-2008-4061

Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Firefox HIGH 10.0
CVE-2008-4062

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.1…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Firefox HIGH 10.0
CVE-2008-4064

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and a…

Fix: after 3.0.1
Fix from $1,950 2008-09-24
Firefox HIGH 9.3
CVE-2008-3837

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mou…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Firefox HIGH 7.8
CVE-2008-4068

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 a…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-3835

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows rem…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-3836

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview a…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-4058EPSS 5%

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remo…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-4059

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chr…

Fix: after 2.0.0.17
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-4060

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create docum…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Firefox MEDIUM 5.0
CVE-2008-4069

The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obt…

Fix: after 2.0.0.16
Fix from $1,600 2008-09-24
Firefox HIGH 7.5
CVE-2008-3198

Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrat…

Mitigation only
Fix from $1,950 2008-07-17
Firefox HIGH 10.0
CVE-2008-2798EPSS 14%

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote a…

Fix: after 2.0.0.14
Fix from $1,950 2008-07-07
Firefox HIGH 10.0
CVE-2008-2799EPSS 6%

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote a…

Fix: after 2.0.0.14
Fix from $1,950 2008-07-07
Firefox HIGH 10.0
CVE-2008-2811EPSS 7%

The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attac…

Fix: after 2.0.0.14
Fix from $1,950 2008-07-07