Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox HIGH 7.5
CVE-2005-1155EPSS 8%

The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="i…

Patch available
Fix from $1,950 2005-05-02
Firefox HIGH 7.5
CVE-2005-1156

Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plug…

Patch available
Fix from $1,950 2005-05-02
Firefox HIGH 7.5
CVE-2005-1157

Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to replace existing search plugins with malicious ones usi…

Patch available
Fix from $1,950 2005-05-02
Firefox HIGH 7.5
CVE-2005-1159

The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the ty…

Patch available
Fix from $1,950 2005-05-02
Firefox MEDIUM 5.1
CVE-2005-0230

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous exten…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.1
CVE-2005-0399EPSS 15%

Heap-based buffer overflow in GIF2.cpp in Firefox before 1.0.2, Mozilla before to 1.7.6, and Thunderbird before 1.0.2, and possibly other application…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.1
CVE-2005-0401

FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, wh…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.1
CVE-2005-0527EPSS 7%

Firefox 1.0 allows remote attackers to execute arbitrary code via plugins that load "privileged content" into frames, as demonstrated using certain X…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.1
CVE-2005-1160

The privileged "chrome" UI code in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to gain privileges by overriding certa…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.0
CVE-2005-0146

Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to obtain sensitive data from the clipboard via Javascript that generates a middle…

Patch available
Fix from $1,600 2005-05-02
Thunderbird MEDIUM 5.0
CVE-2005-0148

Thunderbird before 0.9, when running on Windows systems, uses the default handler when processing javascript: links, which invokes Internet Explorer …

No fix yet
Fix from $1,600 2005-05-02
Mozilla MEDIUM 5.0
CVE-2005-0215

Mozilla 1.6 and possibly other versions allows remote attackers to cause a denial of service (application crash) via a XBM (X BitMap) file with a lar…

Mitigation only
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.0
CVE-2005-0255

String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbird before 1.0.2, such as the nsTSubstring_CharT::Replace function, do not prope…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.0
CVE-2005-0588

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allo…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.0
CVE-2005-0589

The Form Fill feature in Firefox before 1.0.1 allows remote attackers to steal potentially sensitive information via an input control that monitors t…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.0
CVE-2005-0590

The installation confirmation dialog in Firefox before 1.0.1, Thunderbird before 1.0.1, and Mozilla before 1.7.6 allows remote attackers to use Insta…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.0
CVE-2005-0989EPSS 10%

The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attacke…

Patch available
Fix from $1,600 2005-05-02
Firefox MEDIUM 5.0
CVE-2005-1158

Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _sea…

Patch available
Fix from $1,600 2005-05-02
Firefox HIGH 7.5
CVE-2005-0752

The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE at…

Patch available
Fix from $1,950 2005-04-18
Firefox HIGH 7.5
CVE-2005-0592

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a…

Mitigation only
Fix from $1,950 2005-03-25
Firefox MEDIUM 6.5
CVE-2005-0587

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a …

Fix: 1.0.1 / 1.7.6+
Fix from $1,600 2005-03-25
Mozilla MEDIUM 5.0
CVE-2005-0149

Thunderbird 0.6 through 0.9 and Mozilla 1.7 through 1.7.3 does not obey the network.cookie.disableCookieForMailNews preference, which could allow rem…

Patch available
Fix from $1,600 2005-02-15
Firefox HIGH 7.5
CVE-2005-0233EPSS 20%

The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using…

Fix: 1.7.6+
Fix from $1,950 2005-02-08
Firefox HIGH 10.0
CVE-2004-0904EPSS 8%

Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow r…

Mitigation only
Fix from $1,950 2004-12-31
Network Security Services HIGH 7.5
CVE-2004-0826EPSS 23%

Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified recor…

Patch available
Fix from $1,950 2004-12-31
Mozilla MEDIUM 5.1
CVE-2004-0909

Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 may allow remote attackers to trick users into performin…

No fix yet
Fix from $1,600 2004-12-31
Firefox MEDIUM 5.0
CVE-2004-1200

Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript…

No fix yet
Fix from $1,600 2004-12-31
Mozilla MEDIUM 5.0
CVE-2004-1450

Unknown vulnerability in LiveConnect in Mozilla 1.7 beta allows remote attackers to read arbitrary files in known locations.

Patch available
Fix from $1,600 2004-12-31
Firefox MEDIUM 5.0
CVE-2004-2225

Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properl…

Patch available
Fix from $1,600 2004-12-31
Thunderbird MEDIUM 5.0
CVE-2004-2226

Mozilla Mail 1.7.1 and 1.7.3, and Thunderbird before 0.9, when HTML-Mails is enabled, allows remote attackers to determine valid e-mail addresses via…

Patch available
Fix from $1,600 2004-12-31