Vulnerabilities > Mozilla > Firefox > 2.0.0.7

DATE CVE VULNERABILITY TITLE RISK
2011-06-30 CVE-2011-0083 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.
network
low complexity
mozilla CWE-399
critical
10.0
2011-06-30 CVE-2011-2366 Improper Input Validation vulnerability in Mozilla Firefox, Gecko and Thunderbird
Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
network
mozilla CWE-20
4.3
2011-05-07 CVE-2011-0076 Privilege Escalation vulnerability in Mozilla Firefox/SeaMonkey
Unspecified vulnerability in the Java Embedding Plugin (JEP) in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, on Mac OS X allows remote attackers to bypass intended access restrictions via unknown vectors.
network
low complexity
mozilla apple
7.5
2011-05-07 CVE-2011-0073 Improper Input Validation vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
network
low complexity
mozilla CWE-20
critical
10.0
2011-05-07 CVE-2011-0071 Path Traversal vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Directory traversal vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 on Windows allows remote attackers to determine the existence of arbitrary files, and possibly load resources, via vectors involving a resource: URL.
network
low complexity
mozilla microsoft CWE-22
5.0
2011-05-07 CVE-2011-0067 Improper Input Validation vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly implement autocompletion for forms, which allows remote attackers to read form history entries via a Java applet that spoofs interaction with the autocomplete controls.
network
low complexity
mozilla CWE-20
5.0
2011-05-07 CVE-2011-0066 Resource Management Errors vulnerability in Mozilla Firefox and Seamonkey
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mObserverList.
network
low complexity
mozilla CWE-399
critical
10.0
2011-05-07 CVE-2011-0065 Resource Management Errors vulnerability in Mozilla Firefox and Seamonkey
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.
network
low complexity
mozilla CWE-399
critical
10.0
2011-04-15 CVE-2011-1712 Information Exposure vulnerability in Mozilla Firefox and Seamonkey
The txXPathNodeUtils::getXSLTId function in txMozillaXPathTreeWalker.cpp and txStandaloneXPathTreeWalker.cpp in Mozilla Firefox before 3.5.19, 3.6.x before 3.6.17, and 4.x before 4.0.1, and SeaMonkey before 2.0.14, allows remote attackers to obtain potentially sensitive information about heap memory addresses via an XML document containing a call to the XSLT generate-id XPath function.
network
mozilla CWE-200
4.3
2011-03-11 CVE-2011-1187 Information Exposure vulnerability in Google Chrome
Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak."
network
low complexity
google mozilla CWE-200
5.0