Vulnerabilities > Mozilla > Mozilla > 0.9.35

DATE CVE VULNERABILITY TITLE RISK
2004-08-06 CVE-2004-0648 Unspecified vulnerability in Mozilla Firefox, Mozilla and Thunderbird
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.
network
low complexity
mozilla
critical
10.0
2004-03-15 CVE-2004-0191 Cross-Site Scripting vulnerability in Mozilla Browser Zombie Document
Mozilla before 1.4.2 executes Javascript events in the context of a new page while it is being loaded, allowing it to interact with the previous page (zombie document) and enable cross-domain and cross-site scripting (XSS) attacks, as demonstrated using onmousemove events.
network
mozilla
6.8
2003-10-07 CVE-2003-0791 Deserialization of Untrusted Data vulnerability in multiple products
The Script.prototype.freeze/thaw functionality in Mozilla 1.4 and earlier allows attackers to execute native methods by modifying the string used as input to the script.thaw JavaScript function, which is then deserialized and executed.
network
low complexity
mozilla sco CWE-502
critical
9.8
2002-12-31 CVE-2002-2061 Denial-Of-Service vulnerability in Netscape
Heap-based buffer overflow in Netscape 6.2.3 and Mozilla 1.0 and earlier allows remote attackers to crash client browsers and execute arbitrary code via a PNG image with large width and height values and an 8-bit or 16-bit alpha channel.
network
low complexity
mozilla netscape
7.5