Skip to main content

Vendor/product archive

mozilla / firefox CVEs

Beta · best-effort

3,284 CVEs tagged to mozilla / firefox922 Critical, 973 High, 1,311 Medium, 78 Low, 0 Unrated.

CVE-2009-3379

Published Oct 29, 2009

Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possib…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3378

Published Oct 29, 2009

The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3377

Published Oct 29, 2009

Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (appli…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3376

Published Oct 29, 2009

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a downlo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3375

Published Oct 29, 2009

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3374

Published Oct 29, 2009

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on intera…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-3373

Published Oct 29, 2009

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3372

Published Oct 29, 2009

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3371

Published Oct 29, 2009

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3370

Published Oct 29, 2009

Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to pop…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3478

Published Sep 29, 2009

Argument injection vulnerability in (1) src/content/js/connection/sftp.js and (2) src/content/js/connection/controlSocket.js.in in FireFTP Extension 1.0.5 for Firefox allows remot…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3274

Published Sep 21, 2009

Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7244

Published Sep 18, 2009

Mozilla Firefox 3.0.1 and earlier allows remote attackers to cause a denial of service (browser hang) by calling the window.print function in a loop, aka a "printing DoS attack,"…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3079

Published Sep 10, 2009

Unspecified vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to execute arbitrary JavaScript with chrome privileges via vectors invo…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3078

Published Sep 10, 2009

Visual truncation vulnerability in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, allows remote attackers to trigger a vertical scroll and spoof URLs via unspecified Unico…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3077

Published Sep 10, 2009

Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, which allows remote attackers to…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3076

Published Sep 10, 2009

Mozilla Firefox before 3.0.14 does not properly implement certain dialogs associated with the (1) pkcs11.addmodule and (2) pkcs11.deletemodule operations, which makes it easier fo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3075

Published Sep 10, 2009

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 all…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3074

Published Sep 10, 2009

Unspecified vulnerability in the JavaScript engine in Mozilla Firefox before 3.0.14 allows remote attackers to cause a denial of service (memory corruption and application crash)…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3073

Published Sep 10, 2009

Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application cr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3072

Published Sep 10, 2009

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3071

Published Sep 10, 2009

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory co…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3070

Published Sep 10, 2009

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 allow remote attackers to cause a denial of service (memory corruption and application…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3069

Published Sep 10, 2009

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,801-2,825 of 3,284 CVEsPage 113 of 132