Vulnerabilities > Mozilla > Firefox > Critical

DATE CVE VULNERABILITY TITLE RISK
2006-04-14 CVE-2006-1735 Permissions, Privileges, and Access Controls vulnerability in Mozilla products
Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to execute arbitrary code by using an eval in an XBL method binding (XBL.method.eval) to create Javascript functions that are compiled with extra privileges.
network
mozilla CWE-264
critical
9.3
2006-04-14 CVE-2006-1739 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Mozilla products
The CSS border-rendering code in Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain Cascading Style Sheets (CSS) that causes an out-of-bounds array write and buffer overflow.
network
mozilla CWE-119
critical
9.3
2004-12-31 CVE-2004-0904 Integer Overflow vulnerability in Mozilla Browser BMP Image Decoding
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.
network
low complexity
mozilla netscape conectiva redhat
critical
10.0
2004-08-18 CVE-2004-0757 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.
network
low complexity
mozilla
critical
10.0
2004-08-18 CVE-2004-0764 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to hijack the user interface via the "chrome" flag and XML User Interface Language (XUL) files.
network
low complexity
mozilla
critical
10.0
2004-08-06 CVE-2004-0648 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.
network
low complexity
mozilla
critical
10.0