Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 6.8
CVE-2007-1256

Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitr…

Mitigation only
Fix from $1,600 2007-03-03
Firefox MEDIUM 5.8
CVE-2007-0996

The child frames in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 inherit the default charset from the parent wi…

Patch available
Fix from $1,600 2007-02-27
Firefox MEDIUM 5.0
CVE-2007-1116

The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attac…

Patch available
Fix from $1,600 2007-02-26
Firefox MEDIUM 6.8
CVE-2007-0008

Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.…

Fix: after 1.5.0.9
Fix from $1,600 2007-02-26
Firefox MEDIUM 6.8
CVE-2007-0009EPSS 50%

Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x…

Fix: 1.0.8 / 1.5.0.10+
Fix from $1,600 2007-02-26
Firefox MEDIUM 6.8
CVE-2007-0780

browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child wind…

Fix: 1.0.8 / 1.5.0.10+
Fix from $1,600 2007-02-26
Firefox MEDIUM 6.4
CVE-2007-0779

GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 allows remote attackers to spoo…

Patch available
Fix from $1,600 2007-02-26
Firefox MEDIUM 5.4
CVE-2007-0778

The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause …

Fix: 1.0.8 / 1.5.0.10+
Fix from $1,600 2007-02-26
Firefox HIGH 9.3
CVE-2007-0776EPSS 7%

Heap-based buffer overflow in the _cairo_pen_init function in Mozilla Firefox 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1…

Fix: after 2.0.0.1
Fix from $1,950 2007-02-26
Firefox HIGH 9.3
CVE-2007-0777EPSS 8%

The JavaScript engine in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, and SeaMonkey before 1.0.8 allows remot…

Fix: 1.0.8 / 1.5.0.10+
Fix from $1,950 2007-02-26
Firefox HIGH 9.3
CVE-2007-1092EPSS 7%

Mozilla Firefox 1.5.0.9 and 2.0.0.1, and SeaMonkey before 1.0.8 allow remote attackers to execute arbitrary code via JavaScript onUnload handlers tha…

Fix: after 1.0.7
Fix from $1,950 2007-02-26
Firefox MEDIUM 6.8
CVE-2007-1095

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 do not properly implement JavaScript onUnload handlers, which allows remote attackers to ru…

Fix: after 2.0.0.7
Fix from $1,600 2007-02-26
Firefox MEDIUM 6.8
CVE-2007-1084

Mozilla Firefox 2.0.0.1 and earlier does not prompt users before saving bookmarklets, which allows remote attackers to bypass the same-domain policy …

Fix: after 2.0.0.1
Fix from $1,600 2007-02-23
Firefox HIGH 7.5
CVE-2007-0981EPSS 12%

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the sa…

Fix: after 1.5.0.9
Fix from $1,950 2007-02-16
Firefox MEDIUM 6.4
CVE-2007-0802

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain nam…

No fix yet
Fix from $1,600 2007-02-07
Firefox MEDIUM 5.0
CVE-2006-6971

Mozilla Firefox 2.0, possibly only when running on Windows, allows remote attackers to bypass the Phishing Protection mechanism by representing an IP…

No fix yet
Fix from $1,600 2007-02-07
Bugzilla HIGH 7.5
CVE-2007-0792

The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file …

Mitigation only
Fix from $1,950 2007-02-06
Durian Web Application Server HIGH 10.0
CVE-2006-6853EPSS 8%

Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary code via a long string in a cr…

No fix yet
Fix from $1,950 2006-12-31
Firefox HIGH 9.3
CVE-2006-6504EPSS 9%

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to execute arbitrary code by appending a…

Fix: 1.0.7 / 1.5.0.9+
Fix from $1,950 2006-12-20
Firefox HIGH 7.1
CVE-2006-6502

Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9,…

Mitigation only
Fix from $1,950 2006-12-20
Firefox MEDIUM 6.8
CVE-2006-6497

Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, a…

Fix: after 1.5.0.8
Fix from $1,600 2006-12-20
Firefox MEDIUM 6.8
CVE-2006-6498

Multiple unspecified vulnerabilities in the JavaScript engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.…

Mitigation only
Fix from $1,600 2006-12-20
Firefox MEDIUM 6.8
CVE-2006-6500EPSS 8%

Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows…

Fix: 1.0.7 / 1.5.0.9+
Fix from $1,600 2006-12-20
Firefox MEDIUM 6.8
CVE-2006-6501

Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows …

Fix: 1.0.7 / 1.5.0.9+
Fix from $1,600 2006-12-20
Firefox MEDIUM 6.8
CVE-2006-6503

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cr…

Fix: 1.0.7 / 1.5.0.9+
Fix from $1,600 2006-12-20
Seamonkey MEDIUM 6.8
CVE-2006-6505

Multiple heap-based buffer overflows in Mozilla Thunderbird before 1.5.0.9 and SeaMonkey before 1.0.7 allow remote attackers to execute arbitrary cod…

Fix: after 1.5.0.8
Fix from $1,600 2006-12-20
Firefox MEDIUM 6.4
CVE-2006-6585

The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extensi…

Mitigation only
Fix from $1,600 2006-12-15
Firefox MEDIUM 5.0
CVE-2006-6077

The (1) Password Manager in Mozilla Firefox 2.0, and 1.5.0.8 and earlier; and the (2) Passcard Manager in Netscape 8.1.2 and possibly other versions,…

Fix: after 1.5.0.8
Fix from $1,600 2006-11-24
Firefox HIGH 7.5
CVE-2006-5463

Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execut…

Patch available
Fix from $1,950 2006-11-08
Firefox HIGH 7.5
CVE-2006-5747EPSS 6%

Unspecified vulnerability in Mozilla Firefox before 1.5.0.8, Thunderbird before 1.5.0.8, and SeaMonkey before 1.0.6 allows remote attackers to execut…

Patch available
Fix from $1,950 2006-11-08