Vulnerabilities > Mozilla > Firefox > 2.0.7

DATE CVE VULNERABILITY TITLE RISK
2009-06-12 CVE-2009-1832 Code Injection vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame construction."
network
mozilla CWE-94
critical
9.3
2009-04-22 CVE-2009-1311 Information Exposure vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 3.0.9 and SeaMonkey before 1.1.17 allow user-assisted remote attackers to obtain sensitive information via a web page with an embedded frame, which causes POST data from an outer page to be sent to the inner frame's URL during a SAVEMODE_FILEONLY save of the inner frame.
network
mozilla CWE-200
4.3
2009-04-22 CVE-2009-1309 Configuration vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey do not properly implement the Same Origin Policy for (1) XMLHttpRequest, involving a mismatch for a document's principal, and (2) XPCNativeWrapper.toString, involving an incorrect __proto__ scope, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via a crafted document.
network
mozilla CWE-16
4.3
2009-04-22 CVE-2009-1306 Configuration vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
The jar: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not follow the Content-Disposition header of the inner URI, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly other attacks via an uploaded .jar file with a "Content-Disposition: attachment" designation.
network
mozilla CWE-16
4.3
2009-03-27 CVE-2009-1169 Resource Management Errors vulnerability in Mozilla Firefox
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XML file with a crafted XSLT transform.
network
mozilla CWE-399
critical
9.3
2009-03-05 CVE-2009-0821 Resource Management Errors vulnerability in Mozilla Firefox
Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a window.print(window.print()) in the onclick attribute of an INPUT element.
network
low complexity
mozilla CWE-399
5.0
2009-02-04 CVE-2009-0355 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.
network
high complexity
mozilla CWE-264
5.4
2008-07-17 CVE-2008-2933 Improper Input Validation vulnerability in Mozilla Firefox
Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540.
network
high complexity
mozilla CWE-20
2.6
2008-07-07 CVE-2008-2806 Improper Input Validation vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.
network
low complexity
mozilla CWE-20
7.5