Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 5.0
CVE-2005-2704

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCO…

Fix: after 1.7.11
Fix from $1,600 2005-09-23
Firefox MEDIUM 5.0
CVE-2005-2707

Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spawn windows without user interface components such as the address a…

Fix: after 1.7.11
Fix from $1,600 2005-09-23
Firefox HIGH 7.5
CVE-2005-2968EPSS 11%

Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on …

Patch available
Fix from $1,950 2005-09-20
Firefox HIGH 7.5
CVE-2005-2871EPSS 21%

Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote atta…

No fix yet
Fix from $1,950 2005-09-09
Firefox MEDIUM 5.0
CVE-2005-2429

Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbi…

Mitigation only
Fix from $1,600 2005-08-03
Firefox MEDIUM 5.0
CVE-2005-2395

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might …

No fix yet
Fix from $1,600 2005-07-27
Firefox HIGH 7.5
CVE-2005-2260

The browser user interface in Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 does not properly distinguish between user-gener…

Patch available
Fix from $1,950 2005-07-13
Firefox HIGH 7.5
CVE-2005-2261

Firefox before 1.0.5, Thunderbird before 1.0.5, Mozilla before 1.7.9, Netscape 8.0.2, and K-Meleon 0.9 runs XBL scripts even when Javascript has been…

Patch available
Fix from $1,950 2005-07-13
Firefox HIGH 7.5
CVE-2005-2264

Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search targ…

Patch available
Fix from $1,950 2005-07-13
Firefox HIGH 7.5
CVE-2005-2267

Firefox before 1.0.5 allows remote attackers to steal information and possibly execute arbitrary code by using standalone applications such as Flash …

Mitigation only
Fix from $1,950 2005-07-13
Firefox HIGH 7.5
CVE-2005-2269EPSS 6%

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of …

Patch available
Fix from $1,950 2005-07-13
Firefox HIGH 7.5
CVE-2005-2270EPSS 6%

Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by naviga…

Patch available
Fix from $1,950 2005-07-13
Firefox MEDIUM 5.1
CVE-2005-2262EPSS 7%

Firefox 1.0.3 and 1.0.4, and Netscape 8.0.2, allows remote attackers to execute arbitrary code by tricking the user into using the "Set As Wallpaper"…

Mitigation only
Fix from $1,600 2005-07-13
Firefox MEDIUM 5.0
CVE-2005-2263

The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the cont…

Patch available
Fix from $1,600 2005-07-13
Firefox MEDIUM 5.0
CVE-2005-2265EPSS 68%

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 and 7.2 allows remote attackers to cause a denial of service (access violation and cra…

Patch available
Fix from $1,600 2005-07-13
Firefox MEDIUM 5.0
CVE-2005-2266

Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in …

Patch available
Fix from $1,600 2005-07-13
Bugzilla MEDIUM 5.0
CVE-2005-2173

The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the…

Patch available
Fix from $1,600 2005-07-08
Firefox MEDIUM 5.0
CVE-2005-2114

Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote att…

No fix yet
Fix from $1,600 2005-07-05
Firefox MEDIUM 5.0
CVE-2005-0150

Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of t…

Patch available
Fix from $1,600 2005-05-26
Bugzilla MEDIUM 5.0
CVE-2005-1563

Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote a…

Patch available
Fix from $1,600 2005-05-14
Firefox MEDIUM 5.0
CVE-2005-1575

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via th…

Mitigation only
Fix from $1,600 2005-05-14
Firefox HIGH 7.5
CVE-2005-1531

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote att…

Fix: after 1.4
Fix from $1,950 2005-05-12
Firefox HIGH 7.5
CVE-2005-1532EPSS 9%

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, wh…

Mitigation only
Fix from $1,950 2005-05-12
Bugzilla HIGH 7.5
CVE-2005-1564

post_bug.cgi in Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 allows remote authenticated users to "enter bugs into products that are closed for bug…

Patch available
Fix from $1,950 2005-05-12
Bugzilla MEDIUM 5.0
CVE-2005-1565

Bugzilla 2.17.1 through 2.18, 2.19.1, and 2.19.2, when a user is prompted to log in while attempting to view a chart, displays the password in the UR…

Patch available
Fix from $1,600 2005-05-12
Firefox MEDIUM 5.1
CVE-2005-1476EPSS 17%

Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a pr…

Fix: after 1.0.3
Fix from $1,600 2005-05-09
Firefox MEDIUM 5.1
CVE-2005-1477EPSS 15%

The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute…

Patch available
Fix from $1,600 2005-05-09
Firefox HIGH 7.5
CVE-2005-0147

Firefox before 1.0 and Mozilla before 1.7.5, when configured to use a proxy, respond to 407 proxy auth requests from arbitrary servers, which allows …

Patch available
Fix from $1,950 2005-05-02
Firefox HIGH 7.5
CVE-2005-1153

Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL t…

Patch available
Fix from $1,950 2005-05-02
Firefox HIGH 7.5
CVE-2005-1154

Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a …

Patch available
Fix from $1,950 2005-05-02