Vulnerabilities > Mozilla > Firefox > 3.5.2

DATE CVE VULNERABILITY TITLE RISK
2009-10-29 CVE-2009-3379 Remote Memory Corruption vulnerability in Mozilla Firefox 3.5.1/3.5.2/3.5.3
Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
network
low complexity
mozilla
critical
10.0
2009-10-29 CVE-2009-3378 Remote Memory Corruption vulnerability in Mozilla Firefox 3.5.1/3.5.2/3.5.3
The oggplay_data_handle_theora_frame function in media/liboggplay/src/liboggplay/oggplay_data.c in liboggplay, as used in Mozilla Firefox 3.5.x before 3.5.4, attempts to reuse an earlier frame data structure upon encountering a decoding error for the first frame, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly execute arbitrary code via a crafted .ogg video file.
network
mozilla
critical
9.3
2009-10-29 CVE-2009-3377 Remote Memory Corruption vulnerability in Mozilla Firefox
Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
network
low complexity
mozilla
critical
10.0
2009-10-29 CVE-2009-3376 Configuration vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.
network
mozilla CWE-16
critical
9.3
2009-10-29 CVE-2009-3375 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.
network
mozilla CWE-264
4.3
2009-10-29 CVE-2009-3374 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."
network
low complexity
mozilla CWE-264
7.5
2009-10-29 CVE-2009-3373 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Mozilla Firefox and Seamonkey
Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
mozilla CWE-119
critical
10.0
2009-10-29 CVE-2009-3372 Unspecified vulnerability in Mozilla Firefox and Seamonkey
Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.
network
mozilla
critical
9.3
2009-10-29 CVE-2009-3371 Resource Management Errors vulnerability in Mozilla Firefox
Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.
network
low complexity
mozilla CWE-399
critical
10.0
2009-10-29 CVE-2009-3370 Unspecified vulnerability in Mozilla Firefox
Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.
network
low complexity
mozilla
5.0