Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 7.5
CVE-2008-2801

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary…

Fix: after 2.0.0.14
Fix from $1,950 2008-07-07
Firefox HIGH 7.5
CVE-2008-2802

Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via a…

Fix: after 2.0.0.14
Fix from $1,950 2008-07-07
Firefox HIGH 7.5
CVE-2008-2806

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary …

Mitigation only
Fix from $1,950 2008-07-07
Firefox MEDIUM 6.8
CVE-2008-2803

The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does …

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Firefox MEDIUM 6.8
CVE-2008-2810

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assiste…

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Firefox MEDIUM 5.0
CVE-2008-2805

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client compute…

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Firefox MEDIUM 5.0
CVE-2008-2807

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote att…

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Firefox HIGH 10.0
CVE-2008-2786

Buffer overflow in Firefox 3.0 and 2.0.x has unknown impact and attack vectors. NOTE: due to lack of details as of 20080619, it is not clear whether…

No fix yet
Fix from $1,950 2008-06-19
Firefox HIGH 9.3
CVE-2008-2785EPSS 5%

Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as …

Fix: after 2.0.0.15
Fix from $1,950 2008-06-19
Firefox MEDIUM 5.0
CVE-2008-2014

Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in …

Mitigation only
Fix from $1,600 2008-04-30
Firefox HIGH 9.3
CVE-2008-1380

The JavaScript engine in Mozilla Firefox before 2.0.0.14, Thunderbird before 2.0.0.14, and SeaMonkey before 1.1.10 allows remote attackers to cause a…

Fix: after 2.0.0.13
Fix from $1,950 2008-04-17
Firefox MEDIUM 5.0
CVE-2008-1240

LiveConnect in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 does not properly parse the content origin for jar: URIs before sending the…

Fix: after 2.0.0.12
Fix from $1,600 2008-03-28
Firefox HIGH 9.3
CVE-2008-1235EPSS 6%

Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to exec…

Fix: after 2.0.0.12
Fix from $1,950 2008-03-27
Firefox MEDIUM 6.8
CVE-2008-1233

Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to exec…

Fix: after 2.0.0.12
Fix from $1,600 2008-03-27
Firefox MEDIUM 6.8
CVE-2008-1236

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attacke…

Fix: after 2.0.0.12
Fix from $1,600 2008-03-27
Firefox MEDIUM 6.8
CVE-2008-1237

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attacke…

Fix: after 2.0.0.12
Fix from $1,600 2008-03-27
Firefox MEDIUM 5.0
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Ba…

Fix: after 2.0.0.12
Fix from $1,600 2008-03-27
Seamonkey HIGH 7.5
CVE-2008-0304EPSS 6%

Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code v…

Fix: after 2.0.0.9
Fix from $1,950 2008-02-29
Firefox HIGH 9.3
CVE-2008-0420

modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not pr…

Fix: after 2.0.0.11
Fix from $1,950 2008-02-12
Firefox MEDIUM 5.0
CVE-2008-0594

Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses …

Fix: after 2.0.0.11
Fix from $1,600 2008-02-09
Firefox HIGH 9.3
CVE-2008-0412

The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a den…

Fix: after 2.0.0.11
Fix from $1,950 2008-02-08
Firefox HIGH 9.3
CVE-2008-0413

The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a …

Fix: after 2.0.0.11
Fix from $1,950 2008-02-08
Firefox HIGH 9.3
CVE-2008-0419

Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) …

Fix: after 2.0.0.11
Fix from $1,950 2008-02-08
Firefox MEDIUM 5.0
CVE-2008-0367

Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authen…

Fix: after 2.0.0.11
Fix from $1,600 2008-01-19
Firefox HIGH 9.3
CVE-2007-5959EPSS 5%

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 allow remote attackers to cause a denial of servic…

Patch available
Fix from $1,950 2007-11-26
Firefox HIGH 7.1
CVE-2007-5896

Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the …

Mitigation only
Fix from $1,950 2007-11-08
Firefox HIGH 9.3
CVE-2007-5338

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Sc…

Fix: after 2.0.0.7
Fix from $1,950 2007-10-21
Firefox HIGH 9.3
CVE-2007-5045

Argument injection vulnerability in Apple QuickTime 7.1.5 and earlier, when running on systems with Mozilla Firefox before 2.0.0.7 installed, allows …

Fix: after 7.1.5
Fix from $1,950 2007-09-24
Bugzilla HIGH 7.5
CVE-2007-5038

The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the c…

Patch available
Fix from $1,950 2007-09-24
Firefox MEDIUM 5.0
CVE-2007-4879

Mozilla Firefox before Firefox 2.0.0.13, and SeaMonkey before 1.1.9, can automatically install TLS client certificates with minimal user interaction,…

Fix: after 2.0.0.12
Fix from $1,600 2007-09-13