Vulnerabilities > Mozilla > Firefox > 2.0.0.14

DATE CVE VULNERABILITY TITLE RISK
2008-06-19 CVE-2008-2785 Numeric Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows remote attackers to execute arbitrary code via a large number of references to a common CSS object, leading to a counter overflow and a free of in-use memory, aka ZDI-CAN-349.
network
mozilla CWE-189
critical
9.3
2008-05-23 CVE-2008-2419 Resource Management Errors vulnerability in Mozilla Firefox 2.0.0.14
Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.
network
mozilla CWE-399
4.3