Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 5.0
CVE-2006-1742

The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0…

Fix: after 1.7.12
Fix from $1,600 2006-04-14
Firefox MEDIUM 5.0
CVE-2006-1650

Firefox 1.5.0.1 allows remote attackers to spoof the address bar and possibly conduct phishing attacks by re-opening the window to a malicious Shockw…

Mitigation only
Fix from $1,600 2006-04-06
Firefox HIGH 7.8
CVE-2006-1273

Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action h…

Mitigation only
Fix from $1,950 2006-03-19
Bugzilla HIGH 7.5
CVE-2006-0915

Bugzilla 2.16.10 does not properly handle certain characters in the (1) maxpatchsize and (2) maxattachmentsize parameters in attachment.cgi, which al…

Mitigation only
Fix from $1,950 2006-02-28
Bugzilla HIGH 7.5
CVE-2006-0916

Bugzilla 2.19.3 through 2.20 does not properly handle "//" sequences in URLs when redirecting a user from the login form, which could cause it to gen…

Patch available
Fix from $1,950 2006-02-28
Bugzilla MEDIUM 5.5
CVE-2006-0913

SQL injection vulnerability in whineatnews.pl in Bugzilla 2.17 through 2.18.4 and 2.20 allows remote authenticated users with administrative privileg…

Patch available
Fix from $1,600 2006-02-28
Bugzilla MEDIUM 5.5
CVE-2006-0914

Bugzilla 2.16.10, 2.17 through 2.18.4, and 2.20 does not properly handle certain characters in the mostfreqthreshold parameter in duplicates.cgi, whi…

Patch available
Fix from $1,600 2006-02-28
Thunderbird HIGH 9.3
CVE-2006-0884EPSS 7%

The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript securi…

Fix: after 1.0.7
Fix from $1,950 2006-02-24
Firefox MEDIUM 6.4
CVE-2006-0299

The E4X implementation in Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 exposes the interna…

Mitigation only
Fix from $1,600 2006-02-02
Firefox MEDIUM 5.8
CVE-2006-0298

The XML parser in Mozilla Firefox before 1.5.0.1 and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly r…

Patch available
Fix from $1,600 2006-02-02
Firefox MEDIUM 5.1
CVE-2006-0297

Multiple integer overflows in Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote atta…

Mitigation only
Fix from $1,600 2006-02-02
Firefox HIGH 7.5
CVE-2006-0292

The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to c…

Patch available
Fix from $1,950 2006-02-02
Firefox HIGH 7.5
CVE-2006-0293

The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibl…

Patch available
Fix from $1,950 2006-02-02
Firefox HIGH 7.5
CVE-2006-0294

Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary c…

Patch available
Fix from $1,950 2006-02-02
Firefox MEDIUM 5.1
CVE-2006-0295EPSS 71%

Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary cod…

Patch available
Fix from $1,600 2006-02-02
Firefox MEDIUM 5.0
CVE-2006-0296

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remo…

Mitigation only
Fix from $1,600 2006-02-02
Thunderbird MEDIUM 5.1
CVE-2006-0236

GUI display truncation vulnerability in Mozilla Thunderbird 1.0.2, 1.0.6, and 1.0.7 allows user-assisted attackers to execute arbitrary code via an a…

Patch available
Fix from $1,600 2006-01-18
Firefox MEDIUM 6.4
CVE-2005-4685

Firefox and Mozilla can associate a cookie with multiple domains when the DNS resolver has a non-root domain in its search list, which allows remote …

Mitigation only
Fix from $1,600 2005-12-31
Firefox MEDIUM 5.0
CVE-2005-4720EPSS 8%

Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IFRAME element with a large val…

Patch available
Fix from $1,600 2005-12-31
Firefox MEDIUM 5.0
CVE-2005-4809EPSS 6%

Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof the URL in the Status Bar via …

No fix yet
Fix from $1,600 2005-12-31
Bugzilla HIGH 7.5
CVE-2005-4534

The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on te…

Patch available
Fix from $1,950 2005-12-28
Firefox MEDIUM 5.0
CVE-2005-4134EPSS 13%

Mozilla Firefox 1.5, Netscape 8.0.4 and 7.2, and K-Meleon before 0.9.12 allows remote attackers to cause a denial of service (CPU consumption and del…

Fix: after 8.0.40
Fix from $1,600 2005-12-09
Mozilla HIGH 7.8
CVE-2005-3896

Mozilla allows remote attackers to cause a denial of service (CPU consumption) via a Javascript BODY onload event that calls the window function.

No fix yet
Fix from $1,950 2005-11-29
Bugzilla MEDIUM 5.0
CVE-2005-3138

Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows remote attackers to obtain sensitive information such as the list of installed…

Patch available
Fix from $1,600 2005-10-05
Bugzilla MEDIUM 5.0
CVE-2005-3139

Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arb…

Patch available
Fix from $1,600 2005-10-05
Firefox HIGH 7.5
CVE-2005-2701EPSS 7%

Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image…

Fix: after 1.7.11
Fix from $1,950 2005-09-23
Firefox HIGH 7.5
CVE-2005-2702

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code…

Fix: after 1.7.11
Fix from $1,950 2005-09-23
Firefox HIGH 7.5
CVE-2005-2705

Integer overflow in the JavaScript engine in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 might allow remote attackers to execute arbitrary c…

Fix: after 1.7.11
Fix from $1,950 2005-09-23
Firefox MEDIUM 6.4
CVE-2005-2706

Firefox before 1.0.7 and Mozilla before Suite 1.7.12 allows remote attackers to execute Javascript with chrome privileges via an about: page such as …

Fix: after 1.7.11
Fix from $1,600 2005-09-23
Firefox MEDIUM 5.0
CVE-2005-2703

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and poss…

Fix: after 1.7.11
Fix from $1,600 2005-09-23