Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 9.3
CVE-2007-4841

Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allows remote attackers to execute arbitrary commands via a (1…

Fix: after 2.0.0.8
Fix from $1,950 2007-09-12
Bugzilla MEDIUM 5.0
CVE-2007-4538

email_in.pl in Bugzilla 2.23.4 through 3.0.0 allows remote attackers to execute arbitrary commands via the -f (From address) option to the Email::Sen…

Patch available
Fix from $1,600 2007-08-27
Bugzilla MEDIUM 5.0
CVE-2007-4539

The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows r…

Patch available
Fix from $1,600 2007-08-27
Firefox MEDIUM 5.0
CVE-2007-4357

Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the contents of the status bar via a link to a data: URI containing an encoded U…

Fix: after 2.0.0.6
Fix from $1,600 2007-08-15
Firefox HIGH 9.3
CVE-2007-3845EPSS 6%

Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbi…

Mitigation only
Fix from $1,950 2007-08-08
Mozilla CRITICAL 9.8
CVE-2007-4039

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting atta…

Mitigation only
Fix from $2,300 2007-07-27
Firefox MEDIUM 6.8
CVE-2007-4041EPSS 20%

Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL b…

Mitigation only
Fix from $1,600 2007-07-27
Firefox HIGH 9.3
CVE-2007-3734

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to…

Patch available
Fix from $1,950 2007-07-18
Firefox HIGH 9.3
CVE-2007-3735

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers…

Patch available
Fix from $1,950 2007-07-18
Firefox HIGH 9.3
CVE-2007-3737

Mozilla Firefox before 2.0.0.5 allows remote attackers to execute arbitrary code with chrome privileges by calling an event handler from an unspecifi…

Patch available
Fix from $1,950 2007-07-18
Firefox HIGH 9.3
CVE-2007-3738

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrappe…

Patch available
Fix from $1,950 2007-07-18
Firefox MEDIUM 5.0
CVE-2007-3827

Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between…

Mitigation only
Fix from $1,600 2007-07-17
Firefox MEDIUM 6.8
CVE-2007-3656

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote …

No fix yet
Fix from $1,600 2007-07-10
Firefox MEDIUM 6.8
CVE-2007-3285

Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:…

Fix: after 2.0.0.4
Fix from $1,600 2007-06-20
Mozilla MEDIUM 6.4
CVE-2007-3144

Visual truncation vulnerability in Mozilla 1.7.12 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a long h…

No fix yet
Fix from $1,600 2007-06-11
Firefox HIGH 7.8
CVE-2007-3073

Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%…

Fix: after 2.0.0.4
Fix from $1,950 2007-06-06
Firefox HIGH 7.1
CVE-2007-3072

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot enc…

No fix yet
Fix from $1,950 2007-06-06
Firefox HIGH 9.3
CVE-2007-2867

Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and…

Patch available
Fix from $1,950 2007-06-01
Firefox HIGH 9.3
CVE-2007-2868

Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12…

Mitigation only
Fix from $1,950 2007-06-01
Firefox HIGH 7.1
CVE-2007-2671

Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in an HREF attribute in an A ele…

No fix yet
Fix from $1,950 2007-05-14
Firefox HIGH 10.0
CVE-2007-2176

Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. …

No fix yet
Fix from $1,950 2007-04-24
Firefox HIGH 7.8
CVE-2007-2162

(1) Mozilla Firefox 2.0.0.3 and (2) GNU IceWeasel 2.0.0.3 allow remote attackers to cause a denial of service (browser crash or system hang) via Java…

Mitigation only
Fix from $1,950 2007-04-22
Firefox MEDIUM 5.0
CVE-2007-1970

Mozilla Firefox does not warn the user about HTTP elements on an HTTPS page when the HTTP elements are dynamically created by a delayed document.writ…

Mitigation only
Fix from $1,600 2007-04-11
Mozilla HIGH 10.0
CVE-2007-1794

The Javascript engine in Mozilla 1.7 and earlier on Sun Solaris 8, 9, and 10 might allow remote attackers to execute arbitrary code via vectors invol…

Fix: after 1.7
Fix from $1,950 2007-04-02
Firefox MEDIUM 5.0
CVE-2007-1762

Mozilla Firefox 2.0.0.1 through 2.0.0.3 does not canonicalize URLs before checking them against the phishing site blacklist, which allows remote atta…

Mitigation only
Fix from $1,600 2007-03-30
Firefox HIGH 7.5
CVE-2007-1736

Mozilla Firefox 2.0.0.3 does not check URLs embedded in (1) object or (2) iframe HTML tags against the phishing site blacklist, which allows remote a…

Mitigation only
Fix from $1,950 2007-03-28
Firefox MEDIUM 6.8
CVE-2007-1562EPSS 14%

The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to force the client to connect to o…

Fix: 1.5.0.11 / 2.0.0.3+
Fix from $1,600 2007-03-21
Firefox MEDIUM 5.0
CVE-2007-1377EPSS 17%

AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to cause a denial of service (unspec…

No fix yet
Fix from $1,600 2007-03-10
Seamonkey HIGH 9.3
CVE-2007-1282

Integer overflow in Mozilla Thunderbird before 1.5.0.10 and SeaMonkey before 1.0.8 allows remote attackers to trigger a buffer overflow and possibly …

Patch available
Fix from $1,950 2007-03-06
Firefox MEDIUM 6.8
CVE-2007-0994

A regression error in Mozilla Firefox 2.x before 2.0.0.2 and 1.x before 1.5.0.10, and SeaMonkey 1.1 before 1.1.1 and 1.0 before 1.0.8, allows remote …

Fix: 1.0.8 / 1.1.1+
Fix from $1,600 2007-03-06