Vulnerability index

Browse CVEs

2,895 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Firefox MEDIUM 5.0
CVE-2004-2227

Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into d…

Patch available
Fix from $1,600 2004-12-31
Mozilla MEDIUM 5.0
CVE-2004-1316

Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of …

Patch available
Fix from $1,600 2004-12-29
Firefox HIGH 7.5
CVE-2004-0867EPSS 17%

Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…

Mitigation only
Fix from $1,950 2004-12-23
Bugzilla MEDIUM 5.0
CVE-2004-1633

process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenti…

Mitigation only
Fix from $1,600 2004-10-25
Bugzilla MEDIUM 5.0
CVE-2004-1634

show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and…

Patch available
Fix from $1,600 2004-10-25
Firefox MEDIUM 5.0
CVE-2004-1380

Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the d…

Patch available
Fix from $1,600 2004-10-20
Firefox MEDIUM 5.0
CVE-2004-1381EPSS 7%

Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reporte…

Patch available
Fix from $1,600 2004-10-20
Mozilla MEDIUM 5.0
CVE-2004-1614

Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual ele…

No fix yet
Fix from $1,600 2004-10-18
Firefox HIGH 7.5
CVE-2004-0866EPSS 10%

Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…

Patch available
Fix from $1,950 2004-09-16
Mozilla MEDIUM 5.0
CVE-2004-0871

Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same dom…

Mitigation only
Fix from $1,600 2004-09-16
Bugzilla HIGH 10.0
CVE-2003-1042

SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to exec…

Patch available
Fix from $1,950 2004-08-18
Bugzilla HIGH 10.0
CVE-2003-1043

SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges…

Patch available
Fix from $1,950 2004-08-18
Mozilla HIGH 10.0
CVE-2004-0722EPSS 13%

Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allo…

Mitigation only
Fix from $1,950 2004-08-18
Firefox HIGH 10.0
CVE-2004-0757EPSS 5%

Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow r…

Fix: after 1.7
Fix from $1,950 2004-08-18
Firefox HIGH 10.0
CVE-2004-0764

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML…

Fix: after 1.7
Fix from $1,950 2004-08-18
Bugzilla HIGH 10.0
CVE-2004-0769EPSS 7%

Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as original…

Patch available
Fix from $1,950 2004-08-18
Bugzilla HIGH 7.5
CVE-2003-1044

editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is bei…

Patch available
Fix from $1,950 2004-08-18
Bugzilla HIGH 7.5
CVE-2003-1046

describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote at…

Patch available
Fix from $1,950 2004-08-18
Firefox HIGH 7.5
CVE-2004-0765

The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certifica…

Fix: after 1.7
Fix from $1,950 2004-08-18
Firefox HIGH 7.5
CVE-2004-0779

The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only …

Mitigation only
Fix from $1,950 2004-08-18
Mozilla MEDIUM 6.4
CVE-2004-0759

Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an <input type="file"> tag.

Patch available
Fix from $1,600 2004-08-18
Mozilla MEDIUM 6.4
CVE-2004-0760EPSS 9%

Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.

Patch available
Fix from $1,600 2004-08-18
Bugzilla MEDIUM 5.0
CVE-2003-1045

votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on…

Patch available
Fix from $1,600 2004-08-18
Mozilla MEDIUM 5.0
CVE-2004-0758

Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allo…

Patch available
Fix from $1,600 2004-08-18
Firefox MEDIUM 5.0
CVE-2004-0761

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lo…

Fix: after 1.7
Fix from $1,600 2004-08-18
Firefox MEDIUM 5.0
CVE-2004-0762

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive event…

Fix: after 1.7
Fix from $1,600 2004-08-18
Firefox MEDIUM 5.0
CVE-2004-0763EPSS 6%

Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunlo…

Patch available
Fix from $1,600 2004-08-18
Firefox HIGH 10.0
CVE-2004-0648EPSS 5%

Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI refere…

Fix: after 1.7.1
Fix from $1,950 2004-08-06
Bugzilla HIGH 7.5
CVE-2004-0703

Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant membe…

Patch available
Fix from $1,950 2004-07-27
Bugzilla HIGH 7.5
CVE-2004-0707

SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to gr…

Patch available
Fix from $1,950 2004-07-27