Skip to main content

Vendor/product archive

mozilla / firefox CVEs

Beta · best-effort

3,284 CVEs tagged to mozilla / firefox922 Critical, 973 High, 1,311 Medium, 78 Low, 0 Unrated.

CVE-2009-3012

Published Aug 31, 2009

Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to cond…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3007

Published Aug 28, 2009

Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2975

Published Aug 27, 2009

Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2953

Published Aug 24, 2009

Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption) via JavaScript code with a long string value for the hash p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2665

Published Aug 4, 2009

The nsDocument::SetScriptGlobalObject function in content/base/src/nsDocument.cpp in Mozilla Firefox 3.5.x before 3.5.2, when certain add-ons are enabled, does not properly handle…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2664

Published Aug 4, 2009

The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2663

Published Aug 4, 2009

libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and a…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2662

Published Aug 4, 2009

The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitra…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2470

Published Aug 4, 2009

Mozilla Firefox before 3.0.12, and 3.5.x before 3.5.2, allows remote SOCKS5 proxy servers to cause a denial of service (data stream corruption) via a long domain name in a reply.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2654

Published Aug 3, 2009

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls w…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2471

Published Jul 22, 2009

The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome priv…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2469

Published Jul 22, 2009

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2468

Published Jul 22, 2009

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial o…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2467

Published Jul 22, 2009

Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involvin…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2466

Published Jul 22, 2009

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly e…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2465

Published Jul 22, 2009

Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors i…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2463

Published Jul 22, 2009

Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2462

Published Jul 22, 2009

The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly exec…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2479

Published Jul 16, 2009

Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,826-2,850 of 3,284 CVEsPage 114 of 132