Vulnerabilities > Mozilla > Firefox > Low

DATE CVE VULNERABILITY TITLE RISK
2005-03-04 CVE-2005-0593 Remote vulnerability in Mozilla Suite
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote attackers to spoof the SSL "secure site" lock icon via (1) a web site that does not finish loading, which shows the lock of the previous site, (2) a non-HTTP server that uses SSL, which causes the lock to be displayed when the SSL handshake is completed, or (3) a URL that generates an HTTP 204 error, which updates the icon and location information but does not change the display of the original site.
network
high complexity
mozilla
2.6
2005-02-07 CVE-2005-0231 Unspecified vulnerability in Mozilla Firefox 1.0
Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."
network
high complexity
mozilla
2.6
2005-01-24 CVE-2005-0145 Unspecified vulnerability in Mozilla Firefox
Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.
network
high complexity
mozilla
2.6
2004-12-31 CVE-2004-1753 The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.
network
high complexity
mozilla netscape
2.6