Vulnerabilities > Mozilla > Firefox > 1.0.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-09-23 | CVE-2005-2703 | Code Injection vulnerability in Mozilla Firefox and Mozilla Suite Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting. | 5.0 |
2005-09-23 | CVE-2005-2702 | Unspecified vulnerability in Mozilla Firefox and Mozilla Suite Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters. | 7.5 |
2005-09-23 | CVE-2005-2701 | Heap Overflow vulnerability in Mozilla Browser/Firefox XBM Image Processing Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag. | 7.5 |
2005-09-20 | CVE-2005-2968 | Unspecified vulnerability in Mozilla Firefox and Mozilla Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that is provided to the browser on the command line, which is sent unfiltered to bash. | 7.5 |
2005-09-09 | CVE-2005-2871 | Remote Buffer Overflow vulnerability in Mozilla/Netscape/Firefox Browsers Domain Name Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.3 and 7.2, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a hostname with all "soft" hyphens (character 0xAD), which is not properly handled by the NormalizeIDN call in nsStandardURL::BuildNormalizedSpec. | 7.5 |
2005-08-17 | CVE-2005-2602 | Unspecified vulnerability in Mozilla Firefox and Thunderbird Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks. | 2.6 |