Vulnerabilities > Mozilla > Firefox > Low

DATE CVE VULNERABILITY TITLE RISK
2005-05-02 CVE-2005-0142 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g.
local
low complexity
mozilla
2.1
2005-05-02 CVE-2005-0144 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-05-02 CVE-2005-0232 Unspecified vulnerability in Mozilla Firefox 1.0
Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."
network
high complexity
mozilla
2.6
2005-05-02 CVE-2005-0402 Unspecified vulnerability in Mozilla Firefox
Firefox before 1.0.2 allows remote attackers to execute arbitrary code by tricking a user into saving a page as a Firefox sidebar panel, then using the sidebar panel to inject Javascript into a privileged page.
network
high complexity
mozilla
2.6
2005-05-02 CVE-2005-0578 Remote vulnerability in Mozilla Suite
Firefox before 1.0.1 and Mozilla Suite before 1.7.6 use a predictable filename for the plugin temporary directory, which allows local users to delete arbitrary files of other users via a symlink attack on the plugtmp directory.
local
low complexity
mozilla
2.1
2005-05-02 CVE-2005-0584 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0.1 and Mozilla before 1.7.6, when displaying the HTTP Authentication dialog, do not change the focus to the tab that generated the prompt, which could facilitate spoofing and phishing attacks.
network
high complexity
mozilla
2.6
2005-05-02 CVE-2005-0586 Remote vulnerability in Mozilla Suite
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.
network
high complexity
mozilla
2.6
2005-05-02 CVE-2005-0591 Unspecified vulnerability in Mozilla Firefox
Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."
network
high complexity
mozilla
2.6
2005-03-25 CVE-2005-0585 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
network
high complexity
mozilla
2.6
2005-03-23 CVE-2005-0143 Unspecified vulnerability in Mozilla Firefox and Mozilla
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
network
high complexity
mozilla
2.6