Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2004-2227
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into d…
Firefox
Patch available
MEDIUM 5.0
CVE-2004-1316
Heap-based buffer overflow in MSG_UnEscapeSearchUrl in nsNNTPProtocol.cpp for Mozilla 1.7.3 and earlier allows remote attackers to cause a denial of …
Mozilla
Patch available
HIGH 7.5
CVE-2004-0867EPSS 17%
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…
Firefox
Mitigation only
MEDIUM 5.0
CVE-2004-1633
process_bug.cgi in Bugzilla 2.9 through 2.18rc2 and 2.19 from CVS does not check edit permissions on the keywords field, which allows remote authenti…
Bugzilla
Mitigation only
MEDIUM 5.0
CVE-2004-1634
show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and…
Bugzilla
Patch available
MEDIUM 5.0
CVE-2004-1380
Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (background) tabs to launch dialog boxes, which can allow remote attackers to spoof the d…
Firefox
Patch available
MEDIUM 5.0
CVE-2004-1381EPSS 7%
Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reporte…
Firefox
Patch available
MEDIUM 5.0
CVE-2004-1614
Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual ele…
Mozilla
No fix yet
HIGH 7.5
CVE-2004-0866EPSS 10%
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…
Firefox
Patch available
MEDIUM 5.0
CVE-2004-0871
Mozilla does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same dom…
Mozilla
Mitigation only
HIGH 10.0
CVE-2003-1042
SQL injection vulnerability in collectstats.pl for Bugzilla 2.16.3 and earlier allows remote authenticated users with editproducts privileges to exec…
Bugzilla
Patch available
HIGH 10.0
CVE-2003-1043
SQL injection vulnerability in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote authenticated users with editkeywords privileges…
Bugzilla
Patch available
HIGH 10.0
CVE-2004-0722EPSS 13%
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and possibly earlier versions, allo…
Mozilla
Mitigation only
HIGH 10.0
CVE-2004-0757EPSS 5%
Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow r…
Firefox
after 1.7
HIGH 10.0
CVE-2004-0764
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML…
Firefox
after 1.7
HIGH 10.0
CVE-2004-0769EPSS 7%
Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as original…
Bugzilla
Patch available
HIGH 7.5
CVE-2003-1044
editproducts.cgi in Bugzilla 2.16.3 and earlier, when usebuggroups is enabled, does not properly remove group add privileges from a group that is bei…
Bugzilla
Patch available
HIGH 7.5
CVE-2003-1046
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote at…
Bugzilla
Patch available
HIGH 7.5
CVE-2004-0765
The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certifica…
Firefox
after 1.7
HIGH 7.5
CVE-2004-0779
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only …
Firefox
Mitigation only
MEDIUM 6.4
CVE-2004-0759
Mozilla before 1.7 allows remote web servers to read arbitrary files via Javascript that sets the value of an <input type="file"> tag.
Mozilla
Patch available
MEDIUM 6.4
CVE-2004-0760EPSS 9%
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null character (%00) in an FTP URI.
Mozilla
Patch available
MEDIUM 5.0
CVE-2003-1045
votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on…
Bugzilla
Patch available
MEDIUM 5.0
CVE-2004-0758
Mozilla 1.5 through 1.7 allows a CA certificate to be imported even when their DN is the same as that of the built-in CA root certificate, which allo…
Mozilla
Patch available
MEDIUM 5.0
CVE-2004-0761
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote attackers to use certain redirect sequences to spoof the security lo…
Firefox
after 1.7
MEDIUM 5.0
CVE-2004-0762
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive event…
Firefox
after 1.7
MEDIUM 5.0
CVE-2004-0763EPSS 6%
Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunlo…
Firefox
Patch available
HIGH 10.0
CVE-2004-0648EPSS 5%
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI refere…
Firefox
after 1.7.1
HIGH 7.5
CVE-2004-0703
Unknown vulnerability in the administrative controls in Bugzilla 2.17.1 through 2.17.7 allows users with "grant membership" privileges to grant membe…
Bugzilla
Patch available
HIGH 7.5
CVE-2004-0707
SQL injection vulnerability in editusers.cgi in Bugzilla 2.16.x before 2.16.6, and 2.18 before 2.18rc1, allows remote attackers with privileges to gr…
Bugzilla
Patch available