Vulnerabilities > Mozilla > Gecko > Medium

DATE CVE VULNERABILITY TITLE RISK
2011-06-30 CVE-2011-2366 Improper Input Validation vulnerability in Mozilla Firefox, Gecko and Thunderbird
Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
network
mozilla CWE-20
4.3
2004-10-26 CVE-2004-1639 Mozilla Firefox before 0.10, Mozilla 5.0, and Gecko 20040913 allows remote attackers to cause a denial of service (application crash or memory consumption) via a large binary file with a .html extension.
network
low complexity
mozilla
5.0