Vulnerabilities > Mozilla > Firefox > 3.0.5

DATE CVE VULNERABILITY TITLE RISK
2009-02-04 CVE-2009-0357 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.
network
low complexity
mozilla CWE-264
5.0
2009-02-04 CVE-2009-0355 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.
network
high complexity
mozilla CWE-264
5.4
2009-02-04 CVE-2009-0353 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Unspecified vulnerability in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine.
network
low complexity
mozilla CWE-399
critical
10.0
2009-02-04 CVE-2009-0352 Resource Management Errors vulnerability in Mozilla Firefox, Seamonkey and Thunderbird
Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.6, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and destruction of arbitrary layout objects by the nsViewManager::Composite function.
network
low complexity
mozilla CWE-399
critical
10.0
2009-01-22 CVE-2009-0253 Remote Security vulnerability in Mozilla Firefox 3.0.5
Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that moves a crafted element to the current mouse position, related to a "Status Bar Obfuscation" and "Clickjacking" attack.
network
mozilla
6.8
2009-01-08 CVE-2009-0071 Resource Management Errors vulnerability in Mozilla Firefox
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a certain (a) replaceChild or (b) removeChild call, followed by a (1) queryCommandValue, (2) queryCommandState, or (3) queryCommandIndeterm call.
network
high complexity
mozilla CWE-399
2.6
2009-01-02 CVE-2008-5822 Resource Management Errors vulnerability in Mozilla Libxul
Memory leak in Libxul, as used in Mozilla Firefox 3.0.5 and other products, allows remote attackers to cause a denial of service (memory consumption and browser hang) via a long CLASS attribute in an HR element in an HTML document.
network
low complexity
mozilla CWE-399
5.0
2008-12-24 CVE-2008-5715 Improper Input Validation vulnerability in Mozilla Firefox 3.0.5
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash).
network
low complexity
mozilla microsoft CWE-20
5.0