Vulnerabilities > Mozilla > Firefox > 1.0.6

DATE CVE VULNERABILITY TITLE RISK
2006-06-02 CVE-2006-2778 Unspecified vulnerability in Mozilla Firefox and Thunderbird
The crypto.signText function in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to execute arbitrary code via certain optional Certificate Authority name arguments, which causes an invalid array index and triggers a buffer overflow.
network
low complexity
mozilla
5.0
2006-06-02 CVE-2006-2777 Unspecified vulnerability in Mozilla Firefox and Seamonkey
Unspecified vulnerability in Mozilla Firefox before 1.5.0.4 and SeaMonkey before 1.0.2 allows remote attackers to execute arbitrary code by using the nsISelectionPrivate interface of the Selection object to add a SelectionListener and create notifications that are executed in a privileged context.
network
low complexity
mozilla
7.5
2006-06-02 CVE-2006-2776 Unspecified vulnerability in Mozilla Firefox and Thunderbird
Certain privileged UI code in Mozilla Firefox and Thunderbird before 1.5.0.4 calls content-defined setters on an object prototype, which allows remote attackers to execute code at a higher privilege than intended.
network
low complexity
mozilla
7.5
2006-06-02 CVE-2006-2775 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox and Thunderbird
Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allow remote attackers to bypass restrictions by causing a persisted string to be associated with the wrong URL.
network
low complexity
mozilla CWE-264
7.5
2006-04-14 CVE-2006-1738 Unspecified vulnerability in Mozilla products
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) by changing the (1) -moz-grid and (2) -moz-grid-group display styles.
network
low complexity
mozilla
5.0
2006-04-14 CVE-2006-1737 Numeric Errors vulnerability in Mozilla products
Integer overflow in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary bytecode via JavaScript with a large regular expression.
network
mozilla CWE-189
critical
9.3
2006-04-14 CVE-2006-1742 Unspecified vulnerability in Mozilla products
The JavaScript engine in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly handle temporary variables that are not garbage collected, which might allow remote attackers to trigger operations on freed memory and cause memory corruption.
network
low complexity
mozilla
5.0
2006-04-14 CVE-2006-1741 Cross-Site Scripting vulnerability in multiple products
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to inject arbitrary Javascript into other sites by (1) "using a modal alert to suspend an event handler while a new page is being loaded", (2) using eval(), and using certain variants involving (3) "new Script;" and (4) using window.__proto__ to extend eval, aka "cross-site JavaScript injection".
4.3
2006-04-14 CVE-2006-1740 Unspecified vulnerability in Mozilla products
Mozilla Firefox 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to spoof secure site indicators such as the locked icon by opening the trusted site in a popup window, then changing the location to a malicious site.
network
high complexity
mozilla
2.6
2006-04-14 CVE-2006-1739 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Mozilla products
The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.
network
mozilla CWE-119
critical
9.3