Skip to main content

Vendor/product archive

mozilla / firefox CVEs

Beta · best-effort

3,284 CVEs tagged to mozilla / firefox922 Critical, 973 High, 1,311 Medium, 78 Low, 0 Unrated.

CVE-2010-0648

Published Feb 18, 2010

Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0220

Published Jan 7, 2010

The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application cra…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3987

Published Dec 17, 2009

The GeckoActiveXObject function in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, generates different exception messages depending on whether th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3986

Published Dec 17, 2009

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to execute arbitrary JavaScript with chrome privileges by leveraging a re…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3985

Published Dec 17, 2009

Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, and SeaMonkey before 2.0.1, allows remote attackers to associate spoofed content with an invalid URL by setting document.loca…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3979

Published Dec 17, 2009

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.16 and 3.5.x before 3.5.6, SeaMonkey before 2.0.1, and Thunderbird allow remote attackers…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3389

Published Dec 17, 2009

Integer overflow in libtheora in Xiph.Org Theora before 1.1, as used in Mozilla Firefox 3.5 before 3.5.6 and SeaMonkey before 2.0.1, allows remote attackers to cause a denial of s…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3388

Published Dec 17, 2009

liboggplay in Mozilla Firefox 3.5.x before 3.5.6 and SeaMonkey before 2.0.1 might allow context-dependent attackers to cause a denial of service (application crash) or execute arb…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4130

Published Dec 14, 2009

Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the origin domain name of a script…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4129

Published Dec 14, 2009

Race condition in Mozilla Firefox allows remote attackers to produce a JavaScript message with a spoofed domain association by writing the message in between the document request…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4127

Published Dec 2, 2009

Unspecified vulnerability in Wikipedia Toolbar extension before 0.5.9.2 for Firefox allows user-assisted remote attackers to execute arbitrary JavaScript with Chrome privileges vi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4102

Published Nov 29, 2009

Sage 1.4.3 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-doma…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4101

Published Nov 29, 2009

infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4100

Published Nov 29, 2009

Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3978

Published Nov 19, 2009

The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3383

Published Oct 29, 2009

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and appl…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3382

Published Oct 29, 2009

layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3381

Published Oct 29, 2009

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and applica…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3380

Published Oct 29, 2009

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memor…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,776-2,800 of 3,284 CVEsPage 112 of 132