Skip to main content

Vendor/product archive

mozilla / firefox CVEs

Beta · best-effort

3,281 CVEs tagged to mozilla / firefox922 Critical, 970 High, 1,311 Medium, 78 Low, 0 Unrated.

CVE-2009-0354

Published Feb 4, 2009

Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitr…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0253

Published Jan 22, 2009

Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, rela…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5913

Published Jan 20, 2009

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0071

Published Jan 8, 2009

Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash)…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0068

Published Jan 7, 2009

Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open,…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5822

Published Jan 2, 2009

Memory leak in Libxul, as used in Mozilla Firefox 3.0.5 and other products, allows remote attackers to cause a denial of service (memory consumption and browser hang) via a long C…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5715

Published Dec 24, 2008

Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5505

Published Dec 17, 2008

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entitie…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5504

Published Dec 17, 2008

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 2,901-2,925 of 3,281 CVEsPage 117 of 132