Skip to main content

Vendor/product archive

mozilla / firefox CVEs

Beta · best-effort

3,281 CVEs tagged to mozilla / firefox922 Critical, 970 High, 1,311 Medium, 78 Low, 0 Unrated.

CVE-2009-1232

Published Apr 2, 2009

Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption) via an XML document composed of a long series of start-ta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1169

Published Mar 27, 2009

The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and po…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-1044

Published Mar 23, 2009

Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage co…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0821

Published Mar 5, 2009

Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a w…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0358

Published Feb 4, 2009

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information b…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0357

Published Feb 4, 2009

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0356

Published Feb 4, 2009

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers t…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0355

Published Feb 4, 2009

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-ass…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,876-2,900 of 3,281 CVEsPage 116 of 132