Vulnerabilities > Mozilla > Firefox > 1.0.2

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-1156 Remote Script Code Execution vulnerability in Mozilla Suite And Firefox Search Plug-In
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 allows remote attackers to execute arbitrary script and code via a new search plugin using sidebar.addSearchEngine, aka "Firesearching 1."
network
low complexity
mozilla netscape
7.5
2005-05-02 CVE-2005-1155 Code Injection vulnerability in Mozilla Firefox and Mozilla
The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."
network
low complexity
mozilla CWE-94
7.5
2005-05-02 CVE-2005-1154 Cross-Site Scripting vulnerability in Mozilla Suite And Firefox Global Scope Pollution
Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary script in other domains via a setter function for a variable in the target domain, which is executed when the user visits that domain, aka "Cross-site scripting through global scope pollution."
network
low complexity
mozilla
7.5
2005-05-02 CVE-2005-1153 Multiple vulnerability Fixed in SCO OpenServer Release 5.0.7 Maintenance Pack 4 Released -
Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a popup, allows remote attackers to execute arbitrary code via a javascript: URL that is executed when the user selects the "Show javascript" option.
network
low complexity
mozilla
7.5
2005-05-02 CVE-2005-0989 The find_replen function in jsstr.c in the Javascript engine for Mozilla Suite 1.7.6, Firefox 1.0.1 and 1.0.2, and Netscape 7.2 allows remote attackers to read portions of heap memory in a Javascript string via the lambda replace method.
network
low complexity
mozilla netscape
5.0
2005-05-02 CVE-2005-0402 Unspecified vulnerability in Mozilla Firefox
Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.
network
high complexity
mozilla
2.6
2005-04-18 CVE-2005-0752 Remote Script Code Execution vulnerability in Mozilla Firefox PLUGINSPAGE
The Plugin Finder Service (PFS) in Firefox before 1.0.3 allows remote attackers to execute arbitrary code via a javascript: URL in the PLUGINSPAGE attribute of an EMBED tag.
network
low complexity
mozilla
7.5