Skip to main content

Vendor/product archive

mozilla / firefox CVEs

Beta · best-effort

3,284 CVEs tagged to mozilla / firefox922 Critical, 973 High, 1,311 Medium, 78 Low, 0 Unrated.

CVE-2009-2478

Published Jul 16, 2009

Mozilla Firefox 3.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors, related to a "flash bug."

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2477

Published Jul 15, 2009

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certa…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2011

Published Jun 16, 2009

Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.e…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2065

Published Jun 15, 2009

Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2061

Published Jun 15, 2009

Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-2044

Published Jun 12, 2009

Mozilla Firefox 3.0.10 and earlier on Linux allows remote attackers to cause a denial of service (application crash) via a URI for a large GIF image in the BACKGROUND attribute of…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2043

Published Jun 12, 2009

nsViewManager.cpp in Mozilla Firefox 3.0.2 through 3.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1839

Published Jun 12, 2009

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1837

Published Jun 12, 2009

Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to e…

CVSS 7.5 · High

CVE-2009-1835

Published Jun 12, 2009

Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 associate local documents with external domain names located after the file:// substring in a URL, which allows user-assi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1834

Published Jun 12, 2009

Visual truncation vulnerability in netwerk/dns/src/nsIDNService.cpp in Mozilla Firefox before 3.0.11 and SeaMonkey before 1.1.17 allows remote attackers to spoof the location bar…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1828

Published May 29, 2009

Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1827

Published May 29, 2009

The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle el…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1597

Published May 11, 2009

Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow re…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1313

Published Apr 30, 2009

The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) an…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1312

Published Apr 22, 2009

Mozilla Firefox before 3.0.9 and SeaMonkey 1.1.17 do not block javascript: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1311

Published Apr 22, 2009

Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes P…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,851-2,875 of 3,284 CVEsPage 115 of 132